Considering node.js is able to spawn subshells and execute whatever code it wants when running, install scripts pose no additional threat to just running the javascript.
Once the package is installed, it is already too late for a code review, or any mitigation. A well-written worm will never be detected.
It is unexpectedly bad design (or, in case of the JavaScript community, an expectedly bad design).