Putting my conspiracy hat back in the closet, I guess there is plausible reason to believe that someone used PyPI for fraud, CP distribution or some other crime.
accusations and planting evidence are everyday things in some security circles.. plus idiots abuse open systems.. not proof of malfeasance, maybe just a "setup"