I was digging through node_modules today and almost had a heart attack. We are running this code across millions of users right now.
Of course certain things change this balance. Hopefully nuclear power plants dont have NPM in their toolchain. And I believe financial orgs already have quite heavy auditing of dependencies.
It's not that hard to do some superficial review once and do a diff of node_modules when updating npm-shrinkwrap.json for whatever reason.
It's utterly irresponsible to not do so when pulling code from untrusted sources like npm.
Don't pull in dependencies which have many dependencies themselves. There are many projects that pride itself on minimalism and lack of transitive dependencies. Choose those. Etc.