If an attacker can infect the post-install script of an npm package, they can also infect the package source code itself. So if you ever run the project outside the sandbox, you will still get compromised.
It's like saying "I don't trust a software app with an installer, I just want a .zip with the binaries from the same source that I will run myself"
> they can also infect the package source code itself
Which is where the concept of "safe levels" come in. I should be able to install this module in such a way where file operations and process operations are not available to it. That being said, presumably, this types of infiltration would seem to be _much_ easier to spot. "Why is this web framework calling 'spawn'?"
> I just want a .zip with the binaries
I want a .zip with the _code_. Just the code. None of the packaging nonsense. My distribution can handle that.