Seriously: How do we know there aren't dozens or hundreds of comprimsed npm packages installed on every other server out there at this point?
Think xz-utils but even much less sophisticated exploits.
I don't see any systematic protection against this?