> “Since the PyPI index takes precedence, this malicious package was being installed instead of the version from our official repository. This design enables somebody to register a package by the same name as one that exists in a third-party index, and pip will install their version by default.”
Hindsight is 20/20 but what a pants-on-head stupid design.
Also lol lmao at the malware stealing ~/.ssh: https://xkcd.com/1200/