8 ms·
Protestware: “peacenotwar” NPM package drops anti-war message on user's desktop
- batat 5y agoRight now it's included as a dependency only in node-ipc package [1] from the same author (1M weekly downloads/355 dependents). [1] https://www.npmjs.com/package/node-ipc https://www.npmjs.com/package/node-ipc
- jka 5y ago...and node-ipc has been version-locked[1] to a previous release by vue/cli-shared-utils, perhaps one of the more popular downstream consumers of the package. [1] - https://github.com/vuejs/vue-cli/issues/7051 https://github.com/vuejs/vue-cli/issues/7051
- PythagoRascal 5y agoAnother downstream consumer is the Unity Hub (software to download & manage Unity Engine versions) via Vue.
- kstenerud 5y agoHow does this "protest" affect the Russians? How would deliberately annoying your entire user base by creating spam files on their desktop and synced folders without permission possibly help anything? All it will do is cause chaos as people suspect that their dev and CI machines have been infected with a virus, costing time and money to track down what happened. Then they'll be angry at YOU, not the Russians.
- batat 5y agoYet another manifest found in es5-ext: https://github.com/medikoo/es5-ext/issues/116 https://github.com/medikoo/es5-ext/issues/116
- lirantal 5y agoThe full timeline of events and details about how this unfolds are covered here in my write-up: https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/ https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-pack...
- Panin 5y ago[dead]