The article says, “they modified the Linux Mint download page to point to a malicious FTP server” not that they hacked the repository.
Ehrmmm... you consider the misdirecting of a pointer to a site hosting a malicious main iso download page somehow not a repository?
Perhaps if someone posted a link to a Mint iso repo and then showed you the different malicious iso location you might perchance reconsider your position?
Just a thought.
My opinion, its a ‘malicious version’ repo, albeit not a compromised main/standard repo. It’s still a compromised download source.