Mitigate this attack vector by adding:
ignore-scripts=true
https://blog.uxtly.com/getting-rid-of-npm-scripts
Also add it to ~/.npmrc!
Also add it to ~/.npmrc!