Open source package with 1 million monthly downloads stole user credentials