Just read about the compromised ua-parser-js npm package thanks to the Javascript weekly newsletter.
That made me wonder where can I find news specifically about npm vulnerabilities and also get alerts about them (via email or something) ?
Edit: I'm referring to packages that contain actual malware that can infect my computer. Not the long lists of possible vulnerabilities that npm audit reports.
I checked the npm site there is no warning about ua-parser-js on the home page nor the ua-parser-js page itself.