I actually agree this is destroying your credibility as an author and caused me to search all projects author is involved in and blacklist them.
* Despite the motive for the act there is actual malicious code injected in a library without notifying or disclosing any information.
* The whole act was not well thought out. The check is rudimentary to put it gently, or plain naive to say it straight. Not only Russians are targeted but also anyone having vpns or other legitimate reasons to run under Russian IPs. Finally the check is crude and might as well fail at some point, with devastating effect.
* Author seems to be removing github issues, hiding conversations and doing damage control now that this backfires.