Really important write-up. The scariest part is that this kind of attack does not depend on users installing a random plugin — it abuses the trust users already place in the normal update process.
For our Webequipe PDF Search plugin, this is a strong reminder to keep the release process strict: staging tests before release, clear changelogs, limited access to release accounts, final ZIP review, Free/Pro compatibility checks, and post-release monitoring.
Features are important, but for plugins that handle uploaded documents, predictable and transparent updates matter just as much. Thanks for documenting this in detail.