Sept. 6, 2022, 12:11 a.m. | /u/riyakhanna1983

cybersecurity www.reddit.com

**Packj** offers a lightweight sandboxing for "safe installation" of PyPI/NPM/RubyGems packages \[1\]. Specifically, it prevents malicious packages from exfiltrating sensitive data, accessing sensitive files (e.g., SSH keys), and persisting malware.

Full Disclosure: Packj relies on strace, a popular FOSS tool to trace program execution. A proprietary binary blob (sandbox.o) is LD\_PRELOADed to hook into strace and analyze system calls.

1. [https://github.com/ossillate-inc/packj/blob/main/sandbox/README.md](https://github.com/ossillate-inc/packj/blob/main/sandbox/README.md)

cybersecurity installation npm packj pypi rubygems safe sandbox

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

SITEC- Systems Security Administrator- Camp HM Smith

@ Peraton | Camp H.M. Smith, HI, United States

Cyberspace Intelligence Analyst

@ Peraton | Fort Meade, MD, United States

General Manager, Cybersecurity, Google Public Sector

@ Google | Virginia, USA; United States

Cyber Security Advisor

@ H&M Group | Stockholm, Sweden

Engineering Team Manager – Security Controls

@ H&M Group | Stockholm, Sweden