JFrog says six malicious npm packages used hidden install-time execution, JSONKeeper fetches, and sandbox checks to enable remote access.
A tutorial with examples of various access and display types can be seen at crotwell.github.io/seisplotjs. Also see the wiki. Install with npm i --save seisplotjs.