I wrote more about this in <a href="https://twitter.com/vesirin/status/1026807849970614273?s=21" rel="nofollow">https://twitter.com/vesirin/status/1026807849970614273?s=21</a>. Vulnerabilities in package managers is a scary thing.