The attackers swapped the account's email address for an anonymous ProtonMail inbox and pushed the infected packages manually ...