Packages or dependencies with only one maintainer that are this popular have always been an issue, and not just a security one.
What happens when that person can't afford to or doesn't want to run the project anymore? What if they become malicious? What if they sell out? Etc.
It's not just that they demand more, they demand more/faster growth all the time. It doesn't matter that the economy has slowed down to borderline recession, it doesn't matter that they pretty much captured all the market they can, they still need to make more and more money every quarter otherwise they're considered a failure even if they are one of the biggest companies in the world.