We'll see plenty of other NPM disasters this year, and as always, nothing will change because security is an afterthought not a core mission principle.
If it was, NPM wouldn't exist in its current form. It's confusing, adding extra security wouldn't even be that difficult or time consuming, they just don't.
I wish it were possible to take over a project with individuals who actually care. The people in charge of NPM are incompetent at running a secure, large scale distribution system, why they're still allowed to be a part of it is beyond me...
If security isn't your top goal you don't belong in charge of a very important, widely used ecosystem which many rely on.