>npm install playcaptcha Imagine you get pwned for trying this out in your home project and the APT escalates to your company repos and infects your company assets, and then the post mortem comes in and you have to explain this is what infected the company it stack
If you see the code, that dependency just happens to be another file in the repository [0] The only dependency is the 'motion' library. [0]: https://github.com/mortspace/playcaptcha
I'm seeing this from npm, which is a bit different:
https://www.npmjs.com/package/playcaptcha
Not saying the package is malicious, (although it might be, but it's a more likely threat that the devs themselves become infected by a supply chain worm and spread it downstream.) just saying, if you are going to audit it, actually audit it as if you were up against an attacker.