My major concern is how easy it is to include external dependencies via script tags in Electron-based applications and have those external sources be compromised somehow, delivering this attack and ...