I think the next step is creating a PR to another, higher profile package introducing a problematic dependency among other changes. It existing on its own doesn't prove intention of doing that, but it enables it. If I were doing this I'd start by creating an actually useful package and then later change it's behavior, but same principle.
If you were just trying to get people to install it directly you'd go for name collisions / typos / namesquatting in your package name instead.