A cluster of malicious npm packages did not try to run code on install; instead, it appears to have turned package mirrors into a browser-facing trap for social engineering.