When someone republishes an identical (?) copy of a major package under their...
When someone republishes an identical (?) copy of a major package under their own name on #pypi, that's probably malicious right? This is a variation on typosquatting.
Self-replies
Today I learned about the inspector website, browse the contents of a package before you install it! Much easier than the download, unzip, etc.