Разработчики - те ещё тролли
On developer machines, the malware installs a persistent gh-token-monitor daemon (via macOS LaunchAgent or Linux systemd) that polls GitHub every 60 seconds. On receiving a 40X error due to token revocation, the monitor attempts to run rm -rf ~/. The daemon automatically exits after 24 hours without triggering the destructive handler.
Ещё интересный факт:
As with previous Mini Shai-Hulud variants, the malware checks if the system is configured for the Russian language and terminates without exfiltrating data if so.
UPD: там ещё есть аналогичная уязвимость в Python
If the package is executed on a system with location settings in Israel or Iran (via timezone and language) it invokes random.randing(1,6) and if that equals 2, it plays an mp3 file at full volume and runs rm -rf, attempting deleting the files in the system.