Tragedy of the commons - only need a few bad actors to ruin it all for us. Almost all distributors face this problem, from Docker Hub to PyPI. This also reminded me of official Postgres Docker image running a cryptominer in the background [1]
It looks like the miner was installed because the Postgres port got exposed with a weak password.
Are there any aggregators of interesting github issues? Links with a bit of context about them make for some fascinating reads.