That's security theater. The package can still run arbitrary code the moment it's actually used.
Having trusted dependencies at least drastically reduces the risk that 'git clone && npm install' takes over the entire system.
Cooling down dependencies would certainly help, also.