Each package runs its install script inside its own disposable microVM, over the same three decoy credentials, traced at the syscall level. Same setup, three outcomes: watch which secret vaults get opened, and whether anything makes it to the internet. Every event below was recorded live, not scripted.