But then that shifts the issue. You've now got an opaque binary blob being injected into programs. What if it is malicious?
It doesn't really matter anyway, because nobody is reading anything in their dependencies before it gets downloaded. Malware can also be hiding in plain sight in source code, as this attack and many others shows.