In the Node.js world adding a dependency may lead to arbitrary code being executed.
It's bad enough on its own because a bad actor can steal SSH-keys this way, but combined with this exploit they will be able to install a rootkit and compromise your entire system.