Settings

Theme

Protestware: “peacenotwar” NPM package drops anti-war message on user's desktop

github.com

5 points by batat 4 years ago · 7 comments

Reader

kstenerud 4 years ago

How does this "protest" affect the Russians?

How would deliberately annoying your entire user base by creating spam files on their desktop and synced folders without permission possibly help anything?

All it will do is cause chaos as people suspect that their dev and CI machines have been infected with a virus, costing time and money to track down what happened. Then they'll be angry at YOU, not the Russians.

lirantal 4 years ago

The full timeline of events and details about how this unfolds are covered here in my write-up: https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-pack...

batatOP 4 years ago

Right now it's included as a dependency only in node-ipc package [1] from the same author (1M weekly downloads/355 dependents).

[1] https://www.npmjs.com/package/node-ipc

batatOP 4 years ago

Yet another manifest found in es5-ext: https://github.com/medikoo/es5-ext/issues/116

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection