It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.
Are there any languages doing something unique or are especially resilient in this respect?
Oh you mean like the attacks that occur in Rust's cargo?
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...