A reported attempt to hide malicious code in a real repository, paired with a fake account, shows how software trust can be strained long before any payload is confirmed to have landed.