A recent supply chain attack in the npm registry compromised millions of enterprise applications and exposed billions of user records. The attack was met with a sense of inevitability from developers, who believe that such incidents are unavoidable due to the nature of modern web app development. The article highlights the differences in package management and security between the JavaScript ecosystem and other languages like Go and Rust. The npm registry's lack of robust security measures and its reliance on unvetted packages maintained by pseudonymous strangers are seen as contributing factors to the attack.