Not blaming any maintainer here - I also received a similar PR (
https://github.com/foray1010/didyoumean2/pull/1849 same author, 1 hour before mailgen) but did not merge it.
The concern isn’t obvious malicious code in the PR itself, but how cheap it has become to generate a credible replacement library. Once accepted, it becomes part of the trusted supply chain and can be evolved later. Previously this kind of attack required real engineering effort, AI reduces that cost dramatically.