Microsoft owns npmjs.com. They could pay for AI analysis of published version deltas, looking for backdoors and malware.