Is this a supply-chain attack attempt?
A GitHub issue on angular-tree-component questions whether a recently merged pull request adding a mysterious "chore" file to several packages is a supply-chain attack attempt. The commit lacks context, appears not to fix anything, and could log installs or hide malicious code.