Google just rolled up with the bellhop. In case you missed it, Google's new "switching tools" let you paste a one-shot Memory ...
The attackers swapped the account's email address for an anonymous ProtonMail inbox and pushed the infected packages manually ...