Just want to make it perfectly clear, @npmjs is 100% to blame for all the phishing attacks we package authors have to endure. Exposing the email address of authors for shits’n’giggles is 100% to blame for this.
There is no option to prevent your email from being leaked by npm
Father of 2, Author of countless OS projects/libraries (Node.js, React(-Native), WebSockets, Frameworks etc) I shoot stuff online.

