And it’s not just tag managers (GTM/DTM, etc) - React create app command builds a boilerplate with hundreds of packages as dependency.
Has anyone employed any kind of automated scanning to try and catch known malicious code in these?
On the tag manager front, I’m afraid the very premise of letting non-technical people manage code is what makes these a built-in vulnerability. Educating those in control as to risks seems to be the only option, in addition to normal malware scanning you have to do if you run ads.