This OTP/MFA should come from package repositories, before the package is made publicly available. This is needed so that CD stage is not blocked.
OTP/MFA should be scoped to publishing user/org, not the package. How the OTP/MFA client is managed across the maintainers/org, lies in the scope of maintainers/org.
A cooldown of a day, and maybe not updating on weekends will save you from that.
It's time to stop moving at the speed of stupid.