Maybe adware that pops a message that doesn't generate any revenue once after 15 seconds would be more accurate. But I suppose that depends on if a single non-commercial message counts as an ad.
Adware tend to be localized to your own computer instead of working its way into websites you build and pushing itself to all your users.
Perhaps you should reflect why you are pushing adware to YOUR users then. Maybe you should vet YOUR work more carefully instead of pulling in hundreds of dependencies that YOU haven't bothered to vet.
Yes, more visibility into which packages are published/controlled by malware authors helps with vetting (immediate pass instead of reading thousands of lines of code). Yet some people are terrified by that prospect. Really makes you wonder.
"i dont even want to bother reading the code i ship to my users"