Given they use nx my bet is on developer laptop compromise through the nx vscode extension that also compromised GitHub engineer's laptop
the security of their packages should not depend on one laptop being compromised
the security of their packages should not depend on one laptop being compromised