I am totally making an npm package that secretly generates a CP image during the postinstall script.
Developers created this and developers must suffer from this.
Developers created this and developers must suffer from this.
"Thousands of developers swept up in CP ring!" that later turns out to be malware planting CP would go a long way towards fixing this issue.
I really am surprised nobody has made a worm that's sole function is to hit every FBI honeypot in existence and archive it to hidden folders just to prove a point.