Its childish to believe that because you can't fix everything you shouldn't fix anything. Defense in depth.
You don't need to test a compromised package to have it execute code. Importing it anywhere in your tests is enough, even transitively.
It's for sure less likely to run but I doubt it's significantly different in practice.
https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-s...