But on the other hand, these people are not promising anything, do they? Check the MIT/BSD/GPL etc, all of them explicitly state that the software does _not_ come with any kind of guarantee. Harsh reality is: It's user's responsibility to test for those. Noone is forcing you to use this piece of code which is given as-is without any guarantees. Noone is forcing you to update. It might be a dependency, but still it's…
The issue here is spreading actual malware. A developer doesn't owe anything to anyone.
But actually and actively harming others trough actual malware is unethical even if someone didn't promise they wouldn't do so.
If I give someone a piece of food that I expressly don't guarantee anything about, the worse one would assume is that it might be spoiled and I didn't check, or that the ingredients may be of very law quality. Not that I actually purposefully poisoned it.