[On Linux:]
If you didn't give yourself "free" (passwordless) sudo, that's not necessary…
…unless it happened in a week with 2 and a half Linux kernel LPEs.
On linux realistically whatever user you installed the malicious NPM package with has access to everything you care about anyway.
Until it overrides sudo in your $PATH to install malware after you enter your password later.
There a million ways that malware can persist without root.
You should assume other LPEs exist though
There numerous ways to root Linux over the decades
What leads people to believe things like this?
Sudo is security theater.
Malware can make a fake unprivileged sudo that sniffs your password.
function sudo () {