Backdoor found in Python module, not an npm (JavaScript) package. Backdoor collected users’ SSH credentials and sent data to remote server. Developer: Backdoor the result of a hack; it was not intentional. Last week, npm team found a cleverly hidden backdoor that made its way into a popular package. In August 2017, the same npm team also removed 38 JavaScript packages that were caught stealing environment variables from infected projects. Backdoored libraries get backdoored and uploaded on PyPI Python’s official third-party software repository.
Source: https://www.bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/

