Is this related to npm debug and chalk packages being compromised?
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-com...
Seems to have been targeted by the same phishing campaign.
Looks like it. There is already a thread about the Chalk packages here:
https://news.ycombinator.com/item?id=45169657