It looks like security researchers have noticed that open source software package repositories are sort of bad at package name resolution, and that it’s relatively easy to slip a shady package into the public dependency chain when folks are publishing code in the open that references private packages.
So that’s me checking off another item on my “things that have always bothered me but industry practice is to shrug” list.
Also I didn’t see composer mentioned so there may still be bounties to reap from Adobe given Magento’s “every user has their own private packagist repository” thing.