EAC does not prevent this in any way, shape or form.
I see what you mean now about abusing the API - they seem to be invite bombing or similar. This is not what DDoS means. If possible, this is definitely a rate limiting issue to be solved on the backend. EAC does not prevent this.
The client in your last link appears harmless at a glance, though maybe if I dug enough into it I'd find something unsavory. Did you look at what it does?
I don't think you have provided any evidence of harmful modding that will be affected by this patch yet. It's easy enough, on the other hand, to locate the github repositories for the hundreds of harmless mods that tens of thousands of community members use regularly, and which you don't seem to know about if you think these videos suffice to describe what mods are "mostly" used for.