Why should I trust open source today? Packages are routinely hacked, political message or not. I 100% agree this has no place in open source but (1) people subject to the effects of war aren't in most sound state of mind and (2) "npm install" is arbitrarily running pre- and post- hook commands that can do all sorts of fun things on your machine. This commit looks harmless in comparison to packages looking for wallets and AWS credentials.
OSS is used not because it's safe or secure, but because the benefits outweigh the costs.