Various people (such as the creator of the PolyMC fork that is confusingly named PollyMC, notice the amount of 'l's) suggest to change the metadata server: https://github.com/fn2006/PollyMC/commit/121f6b2a4e05fa15b41.... I would personally suggest to use this fork because it does not require access to your MS account, so even if it was compromised the risk would end up being limited in comparison.
Side note: I find it sad to see how people took the chance to spread misinfo.
Example 2: claim that the PolyMC developer received death threats: https://news.ycombinator.com/item?id=33240644, I have not seen any evidence for this claim in the repo nor in the reddit and twitter threads. It might have been in DMs but the developer hasn't said anything about it to my knowledge.