A package registry has the earliest broad view of publication. A CI runner has the first behavioral view inside your blast radius. Treating either as the sole detector confuses two different clocks.
Release analysis can quarantine a version when lifecycle scripts, publisher changes, archive growth, or provenance drift cluster. Runtime telemetry can then show whether npm spawned a postinstall loader, reached an unapproved destination, touched runner memory, or requested delivery authority. The difficult part is not buying another scanner. It is joining those signals while a release is moving and ownership is split across AppSec, platform, identity, and incident response. Otherwise the attestation receives a gold star while the ephemeral crime scene politely deletes itself.
The practical counter-move is bounded: isolate dependency installation from signing, publishing, and deployment authority, then preserve run-to-artifact lineage. Read the full operating model.