I get that it can be useful sometimes. But requiring physical MFA to make a package available to the general public seems like a no-brainer to me.
Users who really want to could opt in to the bleeding edge.