In July, packages were loading malicious DLLs (on Windows targets) [1]. It doesn't appear Lavamoat would help in that scenario. Is that right? If so, how do you mitigate this? Run everything in a container?
[1] https://www.crowdstrike.com/en-us/blog/crowdstrike-falcon-pr...