Researchers analyzed install scripts in npm's 5,000 most-downloaded packages and found only 31 (0.6%) execute code during installation. Most packages that declare install steps either complete without network access, fail due to missing build dependencies, or timeout while fetching binaries. The study reveals the ecosystem's install-time attack surface is concentrated enough for manual review.