Why is this news, and why does it need a name of "RepoJacking" assigned to it when the behaviour is working exactly as designed?
This isn't a novel vulnerability, and I wouldn't say any novel vulnerability research has been conducted here. Sure, there's some value in doing a code search and finding instances where people have automated scripts etc relying on aliases, but the vulnerability lies within these scripts.