Earlier quoted context omitted.
"found out right away"... by people with time to review security bulletins. There's loads of places I could see this slipping through the cracks for months.
There's probably already hundreds of thousands of Jira tickets to fix it with no sprint assigned....
And very, very happy that we're proxying all access to npm through Artifactory, which allowed us to block the affected versions and verify that they were in fact never pulled by any of our builds.