Because: we already do routine malware scanning and audit, and review of every changing dependency that we know of, and their transitive dependencies. The scale and frequency of change is one of the reasons to minimise exposure to the fragmented, chaotic shitshow of the node ecosystem.
When there's an incident - and this is most definitely an incident - we have to do more work to verify there was no inadvertent occurrence, that it did not slip through, etc etc.
What's more, one must necessarily download the shit to inspect it, which means you're potentially now holding an unexploded bomb sitting in your developer laptop, for which possibly the only mitigation is that it's sitting inside a container or virtual machine, and one must be careful not to trigger it.
Due to the destruction of trust, we'll also be making an additional effort to remove and replace this and any other package from the same author, and any repository to which they have contributed has to be considered potentially tainted and subject to additional review.
Since you didn't apparently know any of this, I don't think you have any standing to comment on security team procedures.