Sorry if this is very off topic, but I found it:
It isn't a module we use in Node-RED.
A good reminder for authors of nodes to make use of GitHub's excellent security check extensions that report when a dependency is compromised and should be updated.
Ok, sorry if this was a WOLF call.
I am going through doing catch up on things and I read the intro and it mentioned NPM.