“Even if the malicious package ethers-provider2 is removed, the threat actors made sure their malicious functionality would persist.”

Malicious npm packages patched the locally installed copy of ethers, which has over 350 million downloads, to open a reverse shell. Deleting the bad package leaves the infection in place. You have to reinstall ethers as well.