I cant help but think of the post about stealing password credentials from the site you build by surreptitiously inserting extra code into the published NPM package. Except wasm packages seem like they'd be even harder to detect.
https://hackernoon.com/im-harvesting-credit-card-numbers-and...