No, npm only says you give them a license to allow them to serve the package to users; other than that, you're free to license it however you want.
So the bank shouldn't be able to send DMCA takedown notices, right? Because they granted npm the license to redistribute the package.
I think they can argue that the code is their property and that the employee that published it on NPM had no mandate from the company to do so. So it's effectively "stolen code" in a sense, just as if the employee had done it to harm the company on purpose.
No one would use such a thing. Very few open source code is in the public domain. The only one I can think of off the top of my head is SQLite.
In fairness, the bank in question might use such a thing, because they have difficulty making decisions that abide by their own policies.
There is a `private` setting in the package.json to avoid this situation.