Threat actor attempted to slipstream a malware payload into yt-dlp's GitHub repo | Hacker News Reader