This talk by Mark S. Miller talking about new security confinement tools in Javascript and how Node could make use of them in its packaging to keep users and developers safe is great https://www.youtube.com/watch?v=9Snbss_tawI
Good watch for anyone working on language / package management systems.