i use node/npm moderately
is there a runnable command to determine if the package list has a compromised version of anything?