Feels like swimming against the current tho. Said dev experience poorly emulates actual linux at best.
Also, I’d think twice before running custom windows isos or unvetted scripts.
I've been thinking along similar lines for a while now, among a lot of users there isn't a sense of security 'hygiene' and a lot of trust granted that doesn't have a foundation beyond looking legit (i.e. has a github). The main thing that seems to be stop it happening is a lack of returns compared to going after a corporation or social engineering/phishing to find someone who will give you money. What I do wonder about is supply chain attacks on something used by a lot of smaller projects, which would end up hitting more targets compared to compromising individual small projects.
Be wary, unknown actors are targeting devs. My email that is only exposed in github recieves targeted mails on the regular, maybe randomly or maybe because I released and contributed to several popular code bases.
Dev credentials tend to unlock more doors than hacking a soccer mom.