A solution could be enforcing hardware keys for 2FA for all maintainers if a package has more than XX thousand weekly downloads.
No hardware keys, no new releases.
No hardware keys, no new releases.
They have it implemented.
I created NPM account today and added passkey from my laptop and hardware key as secondary. As I have it configured it asked my for it while publishing my test package.
So the guy either had TOTP or just the pw.
Seems like should be easy to implement enforcement.