This looks promising...
How one developer just broke Node, Babel and thousands of projects in 11 lines of JavaScript
Code pulled from NPM – which everyone was using
"I think was a great disturbance in NPM, as if millions of Stack Overflow copypasters cried out in terror as their remotely hosted scripts were suddenly deleted."
And then security and reliability go up at least ten fold when they fix and self-host.