The headline :chef-kiss:

(The vuln itself is an abuse of symlinking bin scripts in packages. The broader threat will continue until Microsoft starts scanning package data on upload.)

Life raft.

