Three JavaScript libraries found on the npm portal -- plutov-slack-client, nodetest199 and nodetest1010 -- opened shells on the computers of developers who imported the packages into their projects. The npm security team have removed the package, but are warning users that there is no guarantee this will remove all malicious software resulting from installing it.