To be clear, I don't want to sound callous or say that this is, in the long term, the cost of doing business in open source (it absolutely should not be); but if you're a person with a publicly-routable email (say, via git commiter or author metadata), on a long enough timeline, someone awful's liable to find it and use it maliciously.
My opinion (admittedly, not having been on the receiving end of something this pointlessly awful) is that it's better not to fold to these kinds of attacks. These people are basically schoolyard bullies, and usually attention-seekers. Validating their attempts only encourages more behaviour like this.
I hope the former maintainer is doing well, and I hope this message doesn't come off as disrespectful or harmful. If it does, I'm very open to hearing about alternative approaches.