Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing ...