A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.