Some points are valid, but come on, if an attacker has write access to your code, you can't recover from that, ever.
Why is this relevant for this article? The article doesn't say anything about attackers having write access to the source.
> The mitigation is to maintain secure access permissions on all directories and package files in search path to ensure unprivileged users do not have write access to them.
Check out the "yes"es in the "fixed" column in comment at https://bugs.python.org/msg85966
The same is true for module imports... If you have write access to the same directory as the code itself there's all sorts of havoc one can cause beyond merely substituting your own os.py.