And again, npm is also an example of “a singular supply chain [selected] by the author” in this way. On top of what cpuguy83 mentioned, curl | sh is vulnerable to compromise anywhere on the stack serving the script (domain name, host, maybe CDN, GitHub account if it’s just a redirect to GitHub as they regularly are), and coming back to what I originally said, even the real author might decide to serve you a special version of the script that nobody else is getting. You’d never know.
I'm not replying here to say one is better than than the other (npm has obviously had its share of problems) but rather to combat claims that curl|bash is somehow safer, it absolutely is not, in fact it's all the bad stuff about npm without the pretense of being potentially safe.