We built this opensource tool to detect opensource supply chain attacks on npm and pypi.
Feel free to give it a try and contribute to improvements.