It's not just about the packages and whether they are malicious or not. These, so far at least, are not - AFAICT they don't even *claim* do anything at all that is functionally useful to a coder so they are never going to get downloaded; their sole purpose is to earn the uploader some of these TEA tokens which, when amalgamated across a few hundred thousand packages, is presumably worth something to them, or why bother? Now that the jig is up, the people that do like to peddle such malware are probably not looking too kindly on whoever pulled this off.
That's the secondary issue here ; like many similar things, whoever came up with this TEA token either didn't consider, or didn't care about, human nature. Anyone with half a clue, or the slightest care about the integrity of such a scheme, should be well aware by now that if you can earn something of value (which need not be monetary) by doing some online clicks, likes, shares, uploads, or whatever then some asshat is going to try and exploit the system so they can get all the benefits without the effort. If your system isn't baking in countermeasures against that kind of abuse, then it's a PoS that should never have left the drawing board but, all too often, human nature rears its head again and says "ship it anyway!" and the enshitification continues.