> An Istanbul-based bug bounty hunter hypothesized that the npm projects ran by the developer effectively paved the means for the attacker to deploy a reverse shell, by opening up port 5000 on his machine that began "listening" for connections.
Is something blindly connecting to port 5000 and sending a secret payload without verifying what's connected on the other end? That seems like a recipe for chaos.