I absolutely feel for his situation. Right now, the degree to which he could be threatened into allowing a malicious group to push changes in his name should not be taken lightly. Hopefully this article reaches the attention of some of the CISOs at companies who rely on the project, and a path towards a situation where multiple parties have visibility into release management can be explored. And honestly, such a solution might be the best thing to make Denis and his family less of a target.
(In the meantime, pin your core-js dependency, and track https://security.snyk.io/vuln/npm?search=core-js as well as npm audit. Arguably there should be an advisory category for known vulnerable maintenance situation - I'm not sure if such a registry exists. One might say that every open source project is vulnerable in some way, but there's nuance and splash radius to consider here, and core-js does not have much defense-in-depth at the moment.)