Here’s a fairly intricate repo spoofing attack, complete with a bot-powered reputation campaign to promote the repo and get it downloaded.
Weird that they’re recommending reimagining for an infostealer, but sure.
I also appreciate the C2 domain connection to a Winos 4.0 NPM squat: