@Ambarishrh said:

Hope its just the sourceforge and NOT the package itself infected

Sourceforge is a known malware "dealer" that hides malware in things that they download.