And all of them "thought" of security as an after-after-after-after-after-thought.
1. Lifecycle Hook Execution
2. CI/CD Identity Plane Attacks
3. Maintainer Account Takeover and Malicious Publish
4. Self-Replicating npm Worms
Right now you could audit packages and make sure you don’t get the latest version