If you want trust, use a (Linux) distribution as intermediary.
OSS is used not because it's safe or secure, but because the benefits outweigh the costs.
Correction: NPM packages are routinely hacked.
I've been using linux packages for two decades, and not once have they been hacked (to my knowledge). I consider those packages to be infinity more secure than proprietary packages where I and others can't check what's running under the hood.
OSS being safe and secure is one of the primary reasons why I prefer open source to closed source software.
I guess I wonder where you draw the line, and if this sort of incident is acceptable, why, and is the line being drawn arbitrary.
There are deeper issues with NPM: how many developers review or audit any packages they download anymore cause each time they pull a single package, it comes with 3000+ dependencies? I'm being hyperbolic, but "open source" isn't the issue here.
What certification are you even talking about if developers themselves can't be bothered to audit their 3000+ NPM dependencies at first place? It's too much work cause too much dependencies? Well that's the architecture NPM chose. I don't have that issue with Go, PHP or Java package management oddly...
I mean do you hang out in your kitchen hoping that Bezos will come by your house to borrow a cup of sugar?