I think something about the node ecosystem makes it particularly vulnerable. Maybe it's the insane "dry" ethos. Or something else.

Nothing I have ever used has a comparable dependency tree nightmare.