Maybe the developer didn’t actually do this on purpose? I sometimes leave debug code in by accident when I publish as well. It happens. A bcc in plain sight seems like debug to me.
Assuming good intentions (debugging) rather than malice was at play, communication is key: drop the malicious version of the package, publish a fix, and communicate on public channels (blog post, here on HN, social media) about the incident.
A proper timeline (not that AI slop in the OP article) also helps bring back trust.
By the way, this is not specific to MCP, could have happened to any package.