Frankly, if you git clone a compromised repository, I'm not sure that a vulnerability of the class "compromised code in that repository will be executed" is all that major a concern. There are plenty of IDEs that will go autonomously run npm installs (with post-install scripts) for you when they detect a package.json. This isn't all that different than that. They could throw up a warning like "do you trust this repos…
This exploit feels very similar to me. I don't know if there's a specific name for this classification of AutoPlay issues.