The recent NPM situation was a real eye opener for me. I never gave much thought to the attack vectors involoving package managers.
> The post install script can be like any other script the user can run. There's no sandboxing so it can access anything the running user can access.
Wow. This just seems wrong that the script has such far reaching privileges.