I'm worried about this - they state:
We are rolling back to the older cert now, but since the registry is distributed
by a global CDN this process is slower than we’d like, and we don’t want
to break things (further) by rushing the process.
If they roll back to the older cert, every install of npm that was "fixed" via the steps in the last post, or updated to latest (node v10.0.26/npm v1.4.4) will break. Perhaps I am missing something but it sounds as though they intend to follow up breaking most npm installs by breaking most npm installs yet again.