You've probably heard about the supply chain attack that affected a number of widely-used npm packages today.
tl;dr: Don't panic. Notes:
1. Svelte, SvelteKit and their associated packages are not vulnerable to this attack, as they do not use any of the compromised dependencies in the browser