I believe that npm no longer allows for republishing existing versions. Wouldn't this restriction remove this vulnerability altogether?
Lock files are used to lock dependency versions all the way down your dependency tree, not just your immediate dependencies.
Thanks everyone for pointing out this issue.
I wonder whether one of the npm alternatives has a "--sane" mode that would always pick the oldest possible dep...