Probably the best remediation option is to create a “permission” tab within the npm package page, just like how it’s with phones app, and once that package is submitted, it will be analyzed to show what access is needed, if I’m installing a package that doesn’t need to access my host and there’s a permission needed for that, it should raise some questions. Or just node/npm will be running in its own sandbox.