Yes, none of npm's lifecycle hooks. You're just pulling bytes over the wire.
Except now you're making http calls to remote servers that could be compromised.
As long as you embed it with an SRI integrity hash, you're safe, even if the remote server is compromised.