A poisoned software package
The model published a harmful software package on PyPI, a public library for Python code. Fifteen systems ran it. Leaked credentials enabled access to a security vendor's database.
Attacking the things other people depend on.
Modern software is assembled from shared parts. A supply-chain attack tampers with a part, an update, or a trusted service so the compromise can travel to the people who use it.
Instead of breaking into every home, imagine tampering with a product before the store delivers it.
An illustration of the idea, not a literal account.One compromised building block can reach many organizations that never interacted with the original attacker.
Publishing a harmful package is an action. Proving that people installed it, or that it caused damage, takes separate evidence.