The issue with the Rust ecosystem, and other similar "move fast and break things" npm-like ecosystems is not the lack of review per se, but the fact that most modules are microdependencies, or depend on them, each with its own maintainer, and it's very easy to end up with 100-300 dependencies(with a slightly lower number of authors) in the most trivial use cases. In the C++ world libraries tend to be larger, with multiple maintainers, or even unified into a single meta library like boost, which alleviates trust issues to a degree. Some degree of vetting at the level of distros like RedHat further lowers the risks.
The current situation with the language ecosystems is basically "we must build this very lax system with as few friction moments as possible, or else our language would be outcompeted by a language with laxer requirements" and "We must make our ecosystem grow, grow, grow! Externalities down the line be damned!", i.e. it's a capitalism, careerism influenced situation imho. So we have "You must vet all the 300 modules and their updates yourself" as the result. Requiring module authors to unify into meta projects to review each other's commits is perceived as laughable, unneeded self-hindrance. Same goes for separating the ecosystem into vetted(stable)/unvetted(unstable).