@evan Programmers are lazy/busy and barely have time to read the README file, let alone do due diligence on a package they’re importing. Plus, if we have connections in common, asking for any kind of reference is IRL highly dependent on personal whims and vendettas (and comes with no guarantees). For #xy it seems there were other actors “vouching” because nefarious actors will “juice” where needed: build their own network of connections to appear genuine to aid their agenda.