Of the top 10 posts on HN about NPM in the past 30 days[1], 9 are about security problems, and last 1 is about package spam.
[1] https://hn.algolia.com/?dateRange=pastMonth&page=0&prefix=fa...