So by "Just NPM is affected" does that mean yarn is unaffected?
No, anything that connects to npm as an authoritative source for packages. Yarn, pnpm, and npm clients all do.