I'm co-founder of Phylum (https://phylum.io), the group that originally identified/reported this campaign back in June [1] and that Github references [2] in their security alert. Happy to answer any questions about this campaign and any other supply chain attacks.
1. https://blog.phylum.io/sophisticated-ongoing-attack-discover...
2. https://github.blog/2023-07-18-security-alert-social-enginee...