In pretty much all hack scenarios I have seen in over 30 odd years of covering this stuff this is the first time I have thought, WOW that is clever I would never have thought of that or even considered it.
A bit technical but I think a few of you might find this interesting.
arstechnica.com
A bit technical but I think a few of you might find this interesting.

Backdoor in public repository used new form of attack to target big firms
Dependency confusion attacks exploit our trust in public code repositories.
