Packages need to be signed with GPG. Full stop. If anyone is running unsigned executable code blindly, they've already failed. You might as well be running .exe files emailed to you by a Nigerian prince.
https://github.com/npm/npm/pull/4016
Oh. Wow. I'm at a loss for words after finding that... I hope NPM are seriously rethinking this position. shasums are definitely not a substitute for validating gpg signatures by any stretch of the imagination.
Anyway, the worries about package removal are misplaced. If production application builds depend on the central NPM repository, they are set up incorrectly. Dependencies should be proxied via a local dependency repository like Sonatype Nexus or Artifactory. It is unprofessional to have builds set up with dependency directly on a repository not under local control.
If you need to convince someone in charge why you need to do this, I recommend this presentation:
https://www.youtube.com/watch?v=pBJafU0p_Nk
It's good, and worth your hour. TL;DW the six reasons are enumerated at 30:59.