Please stop posting this on every single security incident thread with npm. It was funny once, it's just rehashing the same debate over and over.
How do you propose we address this issue? Instead of policing what people say, are you interested in sharing your or someone else ideas?