There have been quite a few attacks on the NPM ecosystem recently and many packages have been compromised. This tool should help you check if your projects are safe.
Run the script. Either download it, copy-paste it or fork it.
The easiest way is to run it with npx: