And here for some good news in the current software supply chain craziness: https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/ #glassworm
watch out for traffic to 164.92.88[.]210. If you see it you might have an infected host on your network (even though nothing bad will happen anymore, that host is a sinkhole).
