Wow, I also received the same phishing email even though my packages only have a few hundred downloads a week (eg. bsky-embed).
So I guess a lot more accounts/packages might be affected than the ones stated in the article
replies(1):
So I guess a lot more accounts/packages might be affected than the ones stated in the article