and they aren’t wrong to do so.
Browser plug-in author gets bored and sells out customer base is a well tread story.
Takeovers of well known packages are another.
Most of these ecosystems do not offer proper sandboxing for the things we take from them, so it’s easy for things to grow an appendage that abuses our prior assumptions.
Apache’s Java ecosystem is full of consultant abandonware and tripwires.