Earlier quoted context omitted.
Why would the malicious user advertise the email associated with crossenv as kent@doddsfamily.com and not kent@dodds.family? Attacker could control the latter and hand you an evil cert?
One would think you would do more than send an email if you're trying to verify. Websites, Twitter, Github, Keybase, etc.. It would be pretty hard for a bad actor to overtake the real author's entire Google-findable presence (assuming it's a reasonably popular package - why would you typosquat anything obscure). If all you do is send an email, then you haven't really done "due diligence" in any acceptable form.
This idea that everyone will just verify with the author is insane.