At least 187 code packages made available through the JavaScript repository NPM have been infected with a self-replicating worm that steals credentials from developers and publishes those secrets on ...
Usually when AV software finds something, it gives you a name of the virus/worm/trojan/etc. It's a lot easier to find information searching on that name than the name of the infected file.