Thanks Alana.
From what I can see, when using ProGet for a private Chocolatey repo, the login page is exposed to the internet. So if the credentials were brute forced, a new package version could be uploaded and therefore distributed maliciously (on next choco update). As far as I'm aware an API key isn't required to do that.