And all that just to allow internet access for npm and pypi? If you've got the bandwidth and disk space, it's very easy to make an offline mirror of both.

Their artifactory is both a package cache and CVE scanner.

The package cache is allowed to download packages directly from npm but other systems in that network won't be able to.

Basically the LLMs hacked the bastion host.