I don't want to read too much into it, but the person (supposedly) submitting the PR seems to work at 1Password since December last year, as per his Linkedin. (And his Linkedin page has a link to the Github profile that made the PR).
Poor guy, he's probably going to get the third degree now.
I hope this also (at least temporarily until verification of 'bad/good') remove him from the org?
I find this aspect to be an outlier, the other attacker accounts were cutouts. So this doesn't quite make sense to me.