Maintainer accounts were compromised and malicious versions of coa and rc published, running a credential-stealing script.
coa is a dependency of React build tooling; the compromise broke React CI worldwide.
A legitimate package's maintainer account or pipeline was taken over and a malicious version published.
Attacks like this are why dependency provenance matters. Scan your manifests against the Gold database, or add the free CI gate to block risky dependencies before they merge.