Can someone explain what exactly this means?
They have integrations with a bunch of services to recognize the tokens, and disable them. This means malicious users can't copy/paste them, spin up servers and leave you with a big bill. (Ideally, of course it could still happen, but the aim is to prevent that kind of thing.)
I think it’s good because the risk of a package being taken over is low, but very damaging if it occurs in a widely used package.