1 article on this topic.
GitHub and PyPI have each added a time-based control against package poisoning. They shrink the window in which a malicious release can spread, but they do not stop a compromise.