It's funny how left-pad was always brought up as a JS supply chain vuln when that wasn't even malware