Apparently, the surprise package I received was part of what is called a Brushing Scam. I don't think I did myself any damage but we'll see.
I did not click on or even see any QR code…so if what I'm learning on the 'net is true, the only thing the scammers are doing now is to write fake reviews of products and affix my name. Okay — but couldn't they have done that without sending me a box of crappy stuff? What am I missing here?