OW. That's gonna leave a mark.

It sucks that we have this glass-jaw dependency system, which is really the main reason these supply chain attacks work.

Really hard to clean up, too. These days, you (being the blackhat) would likely send agents to leverage every compromised repo/app/Web site, almost the instant it comes online, so even if the original mess is cleaned up, there's still a ton of knock-on compromises.