compromised packages list
https://www.mend.io/blog/npm-supply-chain-attack-packages-compromised-by-self-spreading-malware/
the latest list
https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/shai-hulud-2-packages.csv
support yarn v1, npm, and pnpm