This has nothing to do with NodeJS or NPM. The code is freely distributed, just like any open source repo or package manager may provide. The onus is on those who use it to audit what it actually does.
Except at the granularity of NodeJS packages, it would be nearly impossible to do.