The package you
installed last week
isn’t the same file anymore.
PyPI allows maintainers to re-upload a wheel after publication.
No version bump. No announcement. Just a different SHA256 — and every
pip install since then has been running attacker code.
PyPI Watch alerts you the moment a hash changes.