True, but the fact that NPM seems to be the only repository where packages can be "re-published" further exacerbates the bad practices.
https://status.npmjs.org/incidents/41zfb8qpvrdj
The fact that 9 packages could be "published over" _after_ the left-pad fiasco, shows lack of attention.
Tools should try to foster good practices, instead of worsening bad ones.