Best Detection of 2026 Series: Malicious npm or PyPI Auto-Publish via Stolen Registry Token

Detects package publishing or version creation events on npm or PyPI that originate from non-CI/CD service accounts, suggesting the use of stolen registry authentication tokens by unauthorized entities to push malicious package versions.