Guy has his real name on his github page. Googled him, he has a Wikipedia page, created by a Wikipedia user with the same username as his Github one. Well, I think that says all I need to know about his character.
Is it unauthorised if a user chooses to add the package themselves? This is not being put into anyone's machine clandestinely. It is the software user's responsibility to ensure the software is doing what you expect.
IANAL, but I suspect that it is considered unauthorized as there are many avenues in which a dependency will get updated without a user specifying this exact package and version. I think the key here is that there is clear malicious intent.
The npm ecosystem distributing yet another malicious module is more serious though.