This reminds me of the supply chain attack experts who's only solution seems to be blocking postinstall scripts.
That sounds completely different. Blocking the word 'keygen' accomplishes absolutely nothing and is clearly stupid. Blocking build scripts absolutely stops a major attack vector.
The intent is almost certainly to stop a spam campaign which was using NPM package pages to host links to outside sites. Similar pages have been discussed on HN previously [1].
The fact that there was actual installable software involved was irrelevant to the attacker. All they were after was a way to put their content on a high-reputation domain -- and NPM was perfect for that.