The author of event-stream on npm got so much flak for handing out the package when he couldn't maintain it anymore, yet I see no mention of any concerns here. Aren't the same risks of malicious takeover present, or is the python module environment somehow safer?