It's impractical, on an individual level, to vet your entire dependency tree. Installing something like react alone will put 100+ modules in your dependency tree.
A more mature project will have a 4-figure number of dependencies.
Things like Node Security Platform (which was absorbed by NPM) exist for a reason. There's no reason for every person to vet every single package they use -- it'd be an awful lot of duplicated energy.
If there was no implicit trust in the community, and we had to act as vigilant as you describe, there would be no community.