Attack post-mortem
Case study: replaying colors@1.4.1 and faker@6.6.6 through the Veln gate
January 2022: the original maintainer of colors and faker shipped sabotaged versions to npm. Same publisher, no postinstall, no exfil — just an infinite loop in the main module. Three Veln signals fire on replay; the cooling window and file-tree drift do the work. Verdict: BLOCK.