Earlier quoted context omitted.
I just can't agree with this. The problems npm has are not new, surprising ones. They are happily letting people upload malware. https://my.diffend.io/npm/coa/2.0.3/2.0.4/ In 2021, why on earth does such a change not trigger a review before release?
Trigger a review where and by who?
Then I'd guess that Microsoft has enough information with NPM's history to train an AI. Specially the modifications made in these versions could easily trigger suspicious activity.
Did you look at the diffs?
Also, three years of inactivity and then a sudden upload should easily trigger a manual review, even if it is by automatically opening an issue with a review request on that project's GitHub page.