This vulnerability was reported to NPM in 2016: https://blog.npmjs.org/post/141702881055/package-install-scr... https://www.kb.cert.org/vuls/id/319816 but the NPM response was WAI.
I can't think of an instance where I ran npm install and didn't run some process shortly after that imported the packages.
EDIT: oh I scrolled down a bit further and see you said the exact same thing in a top-level comment hahah, my bad