thumbnail W4SP continues to nest in PyPI: Same supply chain attack, different distribution method