Good reminder to use a password manager as well (as it would also catch the 'npnjs' typo squatted domain too).
Similar incident happened to the HIBP guy who mentioned ignoring the password manager safeguards due to being half asleep while on the plane.
Also keep in mind you can disable install scripts in npm from running (if you happen to not do your development in an isolated environment) via configuring your .npmrc with
> ignore-scripts=true
Stay safe out there