RE: Code added to popular NPM package wiped files in Russia and Belarus

This item was in the news a few days ago. I'd like to know people's thoughts.

I'm torn. On the one hand, it erodes trust in all open source software. On the other hand, it selectively targets the aggressor nations in an illegal and immoral war. But where do we draw the line? If you have access to modify critical open soure software, what happens if, for example, you oppose a state government that passes, or tries to pass, anti-LGBTQ legislation (currently in progress in at least 33 states). Is it then fair game to target computer systems in those states?

And if your problem is that this code affects people not directly involved in the waging of the war, or possibly not even indirectly involved, how does this differ from economic sanctions that do the same thing, but for far greater numbers of people?