There have been a lot of supply-chain attacks on projects, by way of creating fake or tainted node.js packages. The base for this attack is complete anonimity without even signature for the package...
The funding manifest has not provided proof via wellKnown that this link is associated with it. Learn more.
wellKnown