> continued using Artifactory for their sandbox

This is still fine. Infact, they had gone one step ahead by having an internal cluster of artifactory rather public managers like pip. The thing they missed is they didn't revoke the write access to it. Even after the ssrf.

In our[1] or other sandbox providers' sandboxes, by default you have access to npm, pip etc package managers, but only read access.

1. https://instavm.io