NPM package with 3 million weekly downloads had a severe vulnerability