Apparently this was a private repo, not a public one, but the attacker gained access.
Certainly product code is going to conform to the pattern you've described, this sounds to me like some of the random non-product projects that may hit some external non-dbx API were not doing things properly and it flew under the radar for whatever reason. I highly doubt these API keys could have been used for much.
So yes, I agree with you, but here's some context.
Disclaimer: I haven't worked there since 2019