i have updated all of my actively maintained repos that use npm packages in some form to only install package versions that have been published for _at least 7 days_ (this includes transitive deps as well); 7 days is currently my hope that will be enough to catch the some-dev-account-got-compromised-and-published-something-malicious as well as the more sophisticated worm hacks. anyone who currently does not enforce a min release age for deps of at least 3 days imho is simply irresponsible.