A seemingly benign package was published, then updated with a payload used in a chained attack against the Agama cryptocurrency wallet to steal funds.
Demonstrated 'trust-then-poison' — build reputation on a clean package before weaponizing it.
A package created specifically to carry a malicious payload.
Attacks like this are why dependency provenance matters. Scan your manifests against the Gold database, or add the free CI gate to block risky dependencies before they merge.