Unless npm infrastructure will be thoroughly curated and moderated, it always going to stay a high risk threat.