The host who can according to the license continue to host it for the other 99.999% of users. The host for example NPM is the one who owns the service and need not provide the uploader with the privilege of revocation.
Well first by communicating with NPM which could take an extraordinary action to break builds in the case where this is the least bad actions or by doing something logical and providing developers or company contacts to register to receive warnings ideally based on parsing actual dep versions and transmitting a message directly to the designated contact for a project.