Yeah, this is becoming a real issue.
We need better tooling for performing static analysis. I recently updated a version of a package and the audit - which I can in no way perform with any authority - was time consuming because of the extensive dependency tree. I both feel more compelled to do audits, and have started hating them; they're the least fun part of developing OSS, and I really only do it because it's fun. When it stops being fun, I'm going to stop doing it.
That's entirely aside from the fact that it puts a damper on the entire ecosystem for users, of which I'm also clearly one.
The OSS community needs (someone smarter and more informed about infosec than me) needs to come up with a response, or this is going to kill OSS as surely as Microsoft never could.