I also commented on the other issue flagged: https://github.com/RedHatInsights/platform-frontend-ai-toolk...

Also detonated the payload: https://leitwacht.eu/blog/valid-provenance-malicious-package