As far as I could tell, that post was just about one specific SF project that had a vulnerable PHP CMS installed on their web space. It's possible that the more general problem of projects being allowed to install/manage their own software got leveraged into a larger exploit, though.
"sourceforge entry point seems still active."
http://seclists.org/fulldisclosure/2011/Jan/424
http://extraexploit.blogspot.com/2011/01/sourceforge-entry-p...