You know NPM isn’t the only way to install JavaScript packages, right? You can add a GitHub repository directly. Yanking the NPM package doesn’t protect people who are pulling from GitHub directly.
It's a suspicious action, so probably locking the account down until they can get in touch and confirm that's what the user wanted to do, and wasn't hacked etc. Could even be automated between npm and github, a compromise warning or similar. All conjecture though.
Aren't npm and GH all owned by Microsoft anyway?
Yes GH and NPM are part of the same company Microsoft