ahh... we now have nodejs ecosystem attack techniques migrating to other systems as well...

It's not very surprising as the node attacks were very effective at gathering credentials.