npm caches the tarball it installs. The cache was written next to the
archive, inside the store's fetch-<sha> entry. Removing that entry after
publication then had to delete a tree, and on Windows it failed while
Defender still held the fresh tarball copy:
[WinError 145] The directory is not empty: ...\fetch-<sha>\.npm-cache\...
Give npm a throwaway temp cache whose cleanup cannot fail the install,
so the download entry holds only the archive.