Some of them were likely already compromised before these incidents, here's one of the accounts near the top making malicious commits to its own repository before the first hack:
https://github.com/Hancie123/mero_hostel_backend/commit/4bcb...