It was reported to npm at the time, but they chose to ignore it - https://github.com/npm/npm/issues/17724
It was reported to npm at the time, but they chose to ignore it - https://github.com/npm/npm/issues/17724
OP is about the fact that manifest contents of the same package version may differ between package contents and registry and looking at the registry is not sufficient to tell which lifecycle scripts will be triggered for a package.
The issue I repeated was just one vector of executing these script attacks, the attached PoC shows how easy it is to create a supply chain attack with npm (you focusing on the npx part is the red herring)
Npm have ignored it for years and now it's getting more common.
This is not a new problem, you just have another vector.
I came up with a free linter package to try solve it - but no one seemed interested, and here we are 7 later talking about where people are now offering paid services to mitigate it.
(Everyone seems so focused on the blog post and missing the fact since NPM was created you've been able to manipulate it's postinstall script to install malware - at any level, including npms failure to verify the manifest file)