It's probably a better idea to follow the process documented in PEP 541 [1] and contact the PyPI admins to request a transfer of the name. Taking over the domain to impersonate the original owner would look indistinguishable from a supply-chain attack.
[1] https://peps.python.org/pep-0541/#how-to-request-a-name-tran...