Banana Squad exploited GitHub to distribute malicious Python code disguised as legitimate tools