“Three days as the default balances two goals: it pushes you past the window where most of these attacks live.”
Dependabot now waits three days before opening a pull request for a new release, and PyPI blocks uploads to releases older than 14 days. Both are sensible and both are years late. The three day delay works because malicious packages get caught and pulled fast, which is an admission that the ecosystem depends on volunteers spotting attacks after publication. Adding a cooling-off timer is cheap. Actually verifying who publishes a package is the part nobody wants to fund.