> I suspect the repo in question was generated with a year-old LLM

I suspect there are a lot of people running inexpensive models that are searching for vulnerabilities across a lot of projects, probably in an automated way (ex with openclaw or similar) in the hopes of winning a bounty and/or noteriety.

Most bounty programs are aware of this. Many projects have closed their bounty program in response to that type of attack.