While I don't particularly like the idea of stuffing ads into npm logs, I don't have the same visceral negative reaction that many people have in these HN threads on this topic. The overwhelming majority of the people complaining about this are well-paid tech workers writing code for well-funded companies that profit off of open source code without providing any reciprocal value to the open source projects in return.…
We look for 100,000 individual solutions to making rent while FAANG are just sitting there with a quarter trillion plus in cash waiting to benefit from the best everything that emerges from this massive, free R&D pipeline. Take the best ideas, hire the best programmers, copy the best software, adopt the best practices. From top to bottom you could probably find 10,000+ open source contributors across their stacks, and to enable that open source software required even more contributors, and influencing it all was the previous generations of contributors.
I think the best solution is FAANG pay it forward and support the entire opensource R&D pipeline that enables them to hoard so much money. Between them they hire more people than there are open source developers so it's ridiculous they cannot support them all. It's a security issue that they do not support them at all for the most part, like with OpenSSL, like with injecting ads into node modules, like with selling modules to be repurposed as malware. We haven't even found the stuff compromised by state agencies yet.