i can guarantee you npm will externalize the cost of false-positive malware scans to package authors.