Hacker News new | ask | show | jobs
by cube00 276 days ago
postinstall is running on the developer's machine, from an endpoint security perspective, it's the actual developer performing the malicious actions, their machine, their IP address and their location.
1 comments

That's a good point. Thanks