Five AsyncAPI npm packages with 2.9 million weekly downloads were trojanized after a GitHub Actions token theft.