Note: The (legitimate!) plugin was apparently taken over by another author and then an update pushed the malware. The comments here as they stand make it sound like the plugin was always a backdoor, and that's not the case.
Another reason why autoupdates are a double edged sword.