Copied text does not inject bitcoin mining malware three months after I paste it.
Neither does a dependency you don't update, though, which is isomorphic to copied code you never update.
somehow, in the js/npm world, dependencies are updated willy nilly, which is the cause of a lot of that ecosystem's headaches.