Open source malware surged 73% in 2025, with npm as a key target with rising risks in software supply chains and developer environments.