The problem is that it is even possible to push builds from dev machines.
With NPM now supporting OIDC, you can just turn this off now https://docs.npmjs.com/trusted-publishers