Every major JS package manager now supports a minimum release age setting. Set it and your toolchain will refuse to install packages published too recently — before the community has had a chance to catch malicious updates. It's a simple config change that could prevent the next supply chain attack.