I've been saying for years to my friends to never user python apps and npm (node) from github or source without containerizing them, because these types of hacks are very possible and it just needs one to ruin your entire digital life or even professional life.
Just use a container for everything. And in the host, only install official packages from the official repositories. For example, apt, or dnf. Be careful with Homebrew, they don't check a shit. Even further, if you use Linux, prefer to use already containarized distros like Bluefin or similar:
We are in the market of digital gold, Bitcoin. Don't ruin your reputation or the money of your users. Always take maximum precautions when choosing your libraries, and take care of your development environment. Use containers ALWAYS. Also, if you can, use compiled languages, there are many who are very easy to use, like Go. Always review the chain of dependences, and watch the network traffic of you libraries, if it is not a networking library, it should never connect to anywhere, or open ports.

Bluefin
The next generation cloud-native Linux workstation, designed for reliability, performance, and sustainability.
#shitcoins #alby