The malicious npm packages are connected to a campaign that can affect computers running Windows, macOS, and Linux.