> I don't like GitHub's security screener dismissing this report because of the "social engineering" aspect.
Agreed.
I get where it comes from, npm isn't responsible for individual contributors getting social-engineered, but this is much deeper than that, and part of the flaw is with npm's support allowing the password reset to go through.