csv-handler-totally-safe
v1.4.0
Published
Demo package for a supply-chain security conference talk. The postinstall script reads the machine's hosts file (/etc/hosts) at install time to show what npm runs with no approval - locally only, sends no data, and has no dependencies.
Maintainers
Readme
csv-handler-totally-safe
This package is 100% harmless. It exists as a live-demo prop for a conference talk about npm supply-chain attacks and JFrog Curation.
The postinstall script demonstrates what an install hook can do automatically.
It reads the machine's hosts file (/etc/hosts on Unix, the equivalent under
System32 on Windows) and prints its contents — nothing else.
It does not touch ~/.ssh, ~/.npmrc, ~/.aws, or any secrets. The hosts
file is not secret, but it's a live proof that an install-time script can read
arbitrary files off your disk with no approval. Everything is printed
locally only — it sends no data anywhere and has zero dependencies.
The point of the demo: npm install runs lifecycle scripts automatically,
granting them process-level access without any approval.
You just proved it by installing.
Source of the talk: https://emmanuelorozco.com
