That's my understanding of it anyway.
I think it's also just a footgun of the JS community. People tend to jump to "what package do I need to install for this" much quicker instead of thinking "how can I solve this".
Every recent JS developer that is learning through online material is constantly berated with "just install this dep, and this dep, and then this one", to the point where it's normalized to have a dependency that comes with who knows what for something that could be a few lines of code and maybe some witty google-foo.
Regardless, even in case of package managers that don't have install scripts (e.g. Maven) one could simply insert malware directly into library code and have it execute whenever you run tests or your application.
The only true solution would be some sort of sophisticated sandboxing or sophisticated malware detection or distributed code review.