This really illustrates a broad security issue with open source development and methodology. Who vets contributors, maintainers and submissions? Answer: Unknown in many (if not most) cases. Unless you have the time and expertise to do so yourself; it is purely based on trust.
Contributors and their submissions are vetted by maintainers. New maintainers are ideally vetted by existing maintainers. This can obviously break down in undermaintained projects.
This ideal obviously did not happen here.
And there are no consequences for those who fail to do so.