Since there are multiple incidents because of infected npm-packages, I just asked myself if its somehow possible, to prevent the installation of an package, if it contains a certain dependency or if that dependency is somewhere in the chain. Is that possible with npm?
Something really basic in package.json like
{
"prevent":["rc@1.2.9"]
}
... or something in that manner