May be give vet a try. It detected most of the malicious packages within few hours of publishing to npm.
GitHub: https://github.com/safedep/vet