here is how I mitigated the spam for now and the future:
I created a table to count the amount of m.room.create events:
CREATE TABLE room_creation_spam (
user_id text,
hits int
);
ALTER TABLE ONLY room_creation_spam
ADD CONSTRAINT room_creation_spam_pk PRIMARY KEY (user_id);