Yeah, bro, let me just install this random npm from that open source dev, it's totally safe! Besides, foss devs are SO smart, so there is zero chance they'd ever get h-ACK-ed.