I feel that that is one of those ideas that sound great in theory, but is impractical in reality. There are way too many packages with similar names already but are completely valid.
What makes me wonder is why it’s always NPM that’s hit with these kind of things, and not, say, Maven? Arguably the attack surface of Maven is much larger and intrusive (lots of enterprises), but the mechanisms of package distribution are completely different. There are a shitload of scans and sanity checks happening when you push a package to a Maven repo such as Sonatype, which I don’t see as much with NPM (and also Pypi for that matter)
(fwiw, I am responsible for package distribution of all APIs of a reasonably popular timeseries database)