Hmm, that does mean that, in theory, your DNS could be redirected in a MitM attack, and malicious packages could be loaded by NPM. I agree that’s unlikely, but in general, if the dependency server has real TLS certs, it is best to try to verify them properly (and to find out why they won’t verify if there is an error).