> This guy abused Github to distribute malicious code to thousands of projects.
He could've done far, far worse in terms of the technical impact of these changes. It's obvious that he was trying to make a statement, not exfiltrate data to sell on the dark web.
It's scary because, as a FOSS maintainer, your code is your responsibility to do with what you will until it's no longer in the market's interest. You don't have the right to expect any sort of compensation for it, but if your project somehow becomes successful and you upset the natural order, all of the work you were told belongs to you that you should be grateful is so successful without being compensated for is now no longer under your control. There was never a business relationship to sever in the first place.
The market doesn't want to come up with a way to compensate FOSS developers with high-profile projects like these, yet the general expectation is those individuals should just continue working on these libraries for companies to profit off of them.
I wouldn't have handled this situation the way this person did, but we're reaching this point where legitimate protest and speech is being met with erasure and confiscation of your work, and that should scare everybody.
> This guy abused Github to distribute malicious code to thousands of projects.
That's one way to look at it. An alternative view is that a bunch of companies took some free code and shoved it into their apps and then got mad that the free code is causing them problems. Instead of examining the inherent contradictions of the FOSS community, commercial interests would rather just erase the protestor.