The obvious step is to use an existing PyPI or email account. So then you take it, by hacking or social engineering, or you buy it, but that means you need money.
Taking over an existing dormant PyPI account sounds feasible just with password spraying, there must be heaps of test accounts that were created by weak passwords. Although PyPI has been improving security, 2FA is not yet required formally logins, nor is password expiry enforced.