The maintainer's npm account was hijacked and malicious versions published, installing a crypto-miner and a password-stealing trojan on Windows and Linux.
ua-parser-js had ~8M weekly downloads and is a transitive dependency of thousands of projects.
A legitimate package's maintainer account or pipeline was taken over and a malicious version published.
Attacks like this are why dependency provenance matters. Scan your manifests against the Gold database, or add the free CI gate to block risky dependencies before they merge.