To give a more realistic answer to this question, when I was writing an article about npm dependencies[1], I incidentally came upon a case where the developer of node-ipc released a malicious version of the package that affected computers in Russian and Belarusian IPs specifically in response to the Ukraine war[2].
[1]: https://www.preethamrn.com/posts/who-actually-uses-is-odd
[2]: https://www.bleepingcomputer.com/news/security/big-sabotage-...