Working with maintainers (on the GitHub side) there’s definitely been a rise of malware dropper attacks against popular OSS repos, though this is particularly brazen - pressure tactics and all.