Researchers say the malware was in the repository for two weeks, advise precautions to defend against malicious packages.