I would say Javascript's lack of a standard library is at least in part responsible for encouraging npm use, things just spiraled out of control from there.
And before you know it, you have a multitude of distributions to choose from, each with their own issues...
Source available beats open source from a security perspective.