On ~27 November 2018 an npm security vulnerability was announced for all users that depend, either directly or indirectly, on the event-stream package. It was a very targeted attack, that only activated if the Copay bitcoin wallet was installed, whereupon it tried to steal the contents....indirectly, on the event-stream package. It was a very targeted attack...and BoB , depend on an npm package called npm-run-all , which...