Good point. When it comes to npm Trojans you’re probably more likely to find them in dumb and boring deps like Lpad.