Doesn't installing a python package from PyPI (optionally) run some of the code in the package? Like "setup.py" ? I'd take advantage of that if I were injecting malicious code in a module.
That shell script runs 'make && make install' on a couple of bundled dependencies, but in principle it could do anything https://github.com/aws/aws-lambda-python-runtime-interface-c...
https://docs.npmjs.com/cli/v7/commands/npm-install/#ignore-s...
https://docs.npmjs.com/cli/v7/commands/npm-ci/#ignore-script...
It's analagous to downloading vs. running an executable.
It's not the case for wheels though, so you can protect yourself by restricting to binary : --only-binary.
Also doing a pip download is not sensible to this issue, but most people do pip install