The npm packages were available since July, have elaborately obfuscated malicious routines, and rely on a fake CAPTCHA to appear authentic.
This app is like https://github.com/coltonsr77/projects-downloader-P3WS but it will look for a file called "installerready.exe" and it will run it If you want to add ...