I partially agree, but that does mitigate it. The report says the attacker injected a `postinstall` script, which is common.
On the other hand, yes, an attack at code level, or a legit bug wouldn't be prevented.