An npm worm has returned, infecting four packages and stealing tokens while spreading through developers’ publishing rights.