Amplification factor
I have no idea how Toptal works in particular, I'm assuming these packages are meant to be used by their freelance devs. To me this looks like a fairly creative way to amplify your attack reach. Getting GitHub access tokens from freelance developers has the potential to snowball into access to codebases from various different clients.
Similar to breaching an MSP in a way.