Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

101–110 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#101

Earlier quoted context omitted.

The micro package ecosystem is also self-reinforcing: some micro packages were created by the same developers who have spun ownership of these things into more lucrative positions. I've tried to get rid of micro packages in the dependency tree of popular libraries, but because it's a turf war, PRs get closed, and the problem continues.

I don’t think anything will change until large development firms pressurise popular projects to stop the behaviour. I hope you speak with executive and lead developers to highlight the volatility of the ecosystem, like I do, every chance I get.

Node.js just needs a proper standard library and this will stop in no time. Never going to happen though.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#102
post #97
post #92

Earlier quoted context omitted.

I'm sorry, but you have absolutely no idea what you are talking about. Russians have been protesting since 2011, and had protests bigger than that that only resulted in all of the opposition leaders getting jailed/murdered/exiled and thousands of people having criminal cases open against them. Tons of people that protested have left the country due to safety concerns. Belorussians just had a giant wave of protests, w…

I never said 20,000 people should die, please don't put words in other peoples mouths. It's against HN rules. I'm saying if the Russian people showed that they disliked Putin in large enough numbers this would end. (either with him ousted, or him having to kill too many people to hide). Also you are making a FANTASTIC argument for why American/EU imperialism is about to come back in a bad way. Apparently once a dicta…

I'm not saying the country can't change from within, I'm saying two things, one is that you can't change it by attacking random people within it, two is that you have no right to tell people to go face death.

Changing the country takes time and organization, you have to cut through propaganda with the real information, change public opinion, and then organize action. So supporting the opposition and independent journalist, human rights groups that help arrested protesters on one hand, and sanctioning the government and the oligarch on the other might actually do something. Deleting files of some random russians and telling them to go get murdered will not.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#103
post #81

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

[deleted]

Re: NPM package compromised by author: erases files on RU / BY computers on install

#104
post #71
post #3

Earlier quoted context omitted.

I rarely visit HN and mostly lurk here, not sure what you're trying to point out. I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on

>This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on Such precedents should be set, we shouldn't be relying on that chain of trust (as clearly demonstrated here). Updates should be vetted, signed, etc. Fetching stuff random people push to npm is a recipe for disaster.

How are regular developers going to vet the literally 1000s of Node.js dependencies they rely on?

And who's signing these updates? The package owner? Well, he's the one adding malicious code so he can sign whatever he wants.

I'll say it again, Node.js needs a proper standard library like Go that takes care of common needs most people have. It's been improving but it was a historical mistake to let microdependencies run wild.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#105
post #81

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

So basically you're interpreting this clause as "if I want to be a total asshole, I can, and no one is allowed to complain"?

I reject that interpretation entirely. Sure, maybe the author isn't legally liable for any harm here (though I'm not entirely convinced that's the case), but we are all well within our rights to tell him he's an asshole for doing this.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#106
post #81

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

Intent matters. The maintainer very clearly intended to do harm. They abused end user trust which is a common attack vector for many pieces of malware.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#108
post #66

I think a helpful guide is to ask myself: what would admired US and RU astronauts/cosmonauts do? I imagine that they are scientists, engineers, and colleagues, and will treat each other with support, as people of goodwill. There are other people who are active combatants right now, whether or not they want to be, and it is tragic beyond words. I believe that one of the ways that we non-combatants can help is to set a…

This is the sad thing about all of this. Many people are demonizing average Russian citizens for the actions of their government.

When the US invaded Iraq in 2003, I was very much against it, but felt powerless to change the course of my government. (And the US government kept on doing what it felt like, no matter how unjust its actions.) While I was ashamed of my country's actions, I didn't think it would be fair for people in other countries to punish me personally for them.

And this is in the US, a supposed liberal democracy! What chance does your average Russian citizen have of getting a dictator like Putin to change his mind here?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#109
post #52

This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?

It's been eye opening to see how easily we can normalize this type of stuff. Social media is also full of deranged calls for full on war against Russia (!!), war crime apologia, and just a pervasive hysterical discourse. The slope is getting so slippery that honestly it's got to stop. Let statesmen impose the sanctions that they deem necessary, they know better than random people. What ukraine needs is advanced weapo…

[dead]

Re: NPM package compromised by author: erases files on RU / BY computers on install

#110
This seems like a rather silly form of protest. Delete people's files and the only thing you're creating here is more hatred directed at yourself.

If you want to sabotage all Russians for some weird reason, just introduce a race condition that's masqueraded as a compatibility fix for the Russian locale.

If you want to send out a message, take a more peaceful approach. Create file or print out a translated message like ", age , was killed in the illegal Russian invasion of Ukraine on " in Russian. Add a link to a picture or a news article if you want. Still a pretty annoying move, probably universally considered in bad taste by most people, but not illegal or destructive. Add something like "the economic recession is because the Western world opposes the Russian government" to make that clear as well, because the immense inflation will probably hit random citizens hardest. Best case scenario you're informing some ignorant Russians stuck behind state propaganda, worst case scenario you piss off some Russian nationalists who will stop using your library.

In the end, this is just another demonstration of how dangerous modern dependency management is. NPM has been through leftpad, colors, now node-ipc, and there's still no way to prevent it from happening again.

I don't know of any language ecosystem with a package manager that doesn't have this problem as well. Perhaps the more boring/slow software dev requiring OS package managers, because Debian maintainers tend to be a little more level-headed than random Github users? Take your pips, cargos, gems, gradles, composers, and you'll find exactly this vulnerability.

The general consensus seems to be "it's impractical to validate all the code we're pulling in, so there's nothing we can do", which is kind of crazy in my opinion. Yes, modern dev does pull in a billion dependencies for every framework, but doing nothing just isn't a problem.

We're one NPM hack away from global catastrophe as long as we don't find a solution for problems like these.

Post reply on HN