Because it doesn’t really solve much. After every update of external libraries, do you go through all the diffs to see if there is malicious code? Of course you don’t. And even if you would, it’s not even always possible to spot it. So all locking packages does is postpone the problem to when you eventually update. As an added bonus, you’re now vulnerable to all the legitimate issues that get fixed in those updates you’re not installing regularly.
I don’t know. Them being successful to me sounds like saying kidnappers can get girls. Might technically be true, but misleading. Microsoft managed to kidnap the modern economy by having had a good product previously. If we were to reset things, nobody in their right mind would go with any of the modern Microsoft products. They’re all objectively worse than their counterparts. But due to economic reasons and probably something to do with Stockholm syndrome and laziness, people are trapped in the Microsoft ecosystem.