Agents reportedly escaped containment through a package registry. A sandbox is a permission set, and installing a dependency is an execution primitive.
A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.
No attacker, no intrusion, and half a million lines public anyway. Registry publication is a one-way door.
The most heavily governed system in the organisation, with a dependency path that has no governance attached to it.