node-ipc is a recent example from the Node ecosystem. The author released an update with some code that made a request to a geolocation webservice to decide whether to wipe the local filesystem.
Where do I stand on the war? I stand with Ukraine.
Where do I stand on software supply chain issues? I stand with not fucking around with the software supply chain.
I like this comment from u/mailto_devnull (https://www.reddit.com/r/node/comments/tg451e/do_not_use_nod...):