the malicious package was added to PyPi last year in June and has been downloaded 885 times so far.
That's a pretty long time to go undetected. Makes you wonder how many other similar packages there currently are, yet to be discovered, in PyPi, npm and others.
Interesting read. One thing I don't fully get is why does Cloudflare have the airport code in the response headers anyway? I cannot think of a single reason to have it in the response.