• support for optional features and dependencies tied to them, ala cargo. How many npm vulnerabilities are introduced thru the command line parser of a package you only use as a library?
• step away from packag.json. It's fine to keep it for the registry or even runtime, but development should use a file that supports comments.
• some automated version compatibility enforcement via typedefs or registry side tests.
• packages with more than one artifact so types, original source, and platform native artifacts can be published in one package but download only when needed.