APT33 changed their code after a report in March. (Getty) When ‘minimal impact’ isn’t reassuring: lessons from the largest npm supply chain compromise Commentary