If you're curious to see what's going inside these malicious PyPI and NPM packages, we host a catalog of all removed packages for research use. Here are links to some examples of the cached malicious source code, along with the signals of malicious intent detected by Socket:
https://socket.dev/npm/package/shineouts/files/1.12.16-beta....
https://socket.dev/npm/package/@dynamic-form-components/shin...
https://socket.dev/npm/package/eslint-plugin-shein-soc-raw/f...
https://socket.dev/npm/package/@spgy/eslint-plugin-spgy-fe/f...
If you're curious to see more examples of the kind of malicious stuff that is posted regularly to package registries, we have a live updating list here: https://socket.dev/npm/issue/gptSecurity
[Disclosure: I'm founder of Socket]