Microsoft either needs to become a better steward of NPM or hand it off to a foundation that can properly maintain it.
If they really believe their AI is that good and security practices and tooling that solid, why can't they automatically flag this stuff? I am sure they can, but once flagged a human has to check and that seems costly?
Good plan - I'm sure they'll get right on it after solving the virus and malware issues on their mainline OS.