Because there is a much larger number of small libraries that end up in every project somewhere down the tree. So: higher count of opportunities.
Because JS is much more popular than any other language and is used in virtually every web project. So: higher impact when successfully executing a supply chain attack. (this is the same reason why Windows has more viruses than linux or osx: not because linux and osx are intrinsically more secure - even if they are, that's never going to be the main factor - but because there are a lot more tech illiterate users with Windows than the others)
NPM isn't particularly less secure, it's just more attractive to exploit.