Explainer
Installing a Package Runs Its Code. That Is the Design, Not the Attack.
CrowdStrike has started intercepting npm install and pip install at the endpoint, blocking a package before its embedded scripts can run. That the defence has moved to the last moment before execution is an admission about everything upstream of it.
