No Preventative Measures (NPM)
You can host your own NPM reg, and examine every package, but your manager probably is NOT going to go for that.
Sounds like something a union should enforce as part of a drive to protect programmer professionalism.