We (https://phylum.io) actually open sourced our sandbox for this exact purpose.
https://github.com/phylum-dev/birdcage
It's baked into our CLI and supports limiting access to network, disk, etc. during package installation. For example, running something like
phylum npm install react
Will perform the installation in a way that disallows access to disk and network that aren't explicitly approved. This prevents malicious packages from grabbing and exfiltrating things like developer SSH keys during package install.