Package manager incidents (like leftpad) have shown that just because it's open source doesn't mean it can't do damage to your project.