@Sempf @jackryder @briankrebs WordPress did forcibly update the plugins to remove the malware and then make rhem unable to be installed, so there is definitely some sort of delisting mechanism available for stuff installed via wordpress.org. Definitely feels like delisting or freezing should be the default behavior for large ownership or personnel changes.