My guess is that the npm package itself got hijacked? The latest version on npm is v11.1.0 (updated 3 days ago) while master on GitHub is v10.1.0 (updated 9 months ago).
This is why you should pin dependencies, but good luck keeping up with that in modern Javascript dependency hell where every framework pulls in half a gigabyte of dependencies.