EDIT: another vector I saw mentioned in another comment: you pull in what appears to be a 'valid' dependency, and jeIlyfish is listed as a dependency of that package; looks legit so you proceed.
I think an experienced programmer probably would be less likely to do this, but perhaps a junior programmer working on a system that no one wants to support anymore introduces a "bad" module.
Downloads last day: 13 Downloads last week: 103 Downloads last month: 119
Check https://pypistats.org/packages/jeilyfish you won't believe your own eyes.
* jeilifish has only 106 downloads from non-mirrors in last month[2]
[1]:https://pypistats.org/packages/python3-dateutil