Earlier quoted context omitted.
How are regular developers going to vet the literally 1000s of Node.js dependencies they rely on? And who's signing these updates? The package owner? Well, he's the one adding malicious code so he can sign whatever he wants. I'll say it again, Node.js needs a proper standard library like Go that takes care of common needs most people have. It's been improving but it was a historical mistake to let microdependencies r…
> How are regular developers going to vet the literally 1000s of Node.js dependencies they rely on? Perhaps they shouldn't be relying on thousands of NPM packages. It's not difficult to write JS code that doesn't `npm install` the entire package ecosystem.
NPM package compromised by author: erases files on RU / BY computers on install
151–160 of 188 posts
Re: NPM package compromised by author: erases files on RU / BY computers on install
#152Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233
Plenty of existing ransomwares delete user files on everything- but -RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".
Re: NPM package compromised by author: erases files on RU / BY computers on install
#153Earlier quoted context omitted.
This is the sad thing about all of this. Many people are demonizing average Russian citizens for the actions of their government. When the US invaded Iraq in 2003, I was very much against it, but felt powerless to change the course of my government. (And the US government kept on doing what it felt like, no matter how unjust its actions.) While I was ashamed of my country's actions, I didn't think it would be fair fo…
Majority of average Russian citizens support their goverment actions against Ukraine. So in my book, they are also responsible.
That is a pretty bold claim to be made without any supporting evidence.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#154Honestly a very harmful sort of "doing something about it". As if deleting someone's (presumably, normal people) files will make them more understanding of the difficulties in the ongoing conflict. Lying about it is also petty, as seen below. Malicious software is malicious regardless of any intentions and should be prosecuted as such. And if one really feels obliged to make their part as they wish, there's many exam…
Re: NPM package compromised by author: erases files on RU / BY computers on install
#155Earlier quoted context omitted.
>This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on Such precedents should be set, we shouldn't be relying on that chain of trust (as clearly demonstrated here). Updates should be vetted, signed, etc. Fetching stuff random people push to npm is a recipe for disaster.
How are regular developers going to vet the literally 1000s of Node.js dependencies they rely on? And who's signing these updates? The package owner? Well, he's the one adding malicious code so he can sign whatever he wants. I'll say it again, Node.js needs a proper standard library like Go that takes care of common needs most people have. It's been improving but it was a historical mistake to let microdependencies r…
Re: NPM package compromised by author: erases files on RU / BY computers on install
#156People focus on the attack itself and reasons behind it. I feel that we are missing the bigger picture here: these type of supply chain attack in the open source world is a systematic problem. It’s a direct result of assumptions baked into services such as npm, pypi, rubygems, etc and assumptions people have regarding 3rd party dependencies. The blast radius is monstrously giant. We seem to be still very naive in the…
It's insane how much legal liability a company is at for agreeing to so many unread licenses. And how much attack surface they're exposing themselves to with their sprawling dependency chains.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#157This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?
When your government uses hospital locations as a target list and drop bombs on shelters, I don’t care if your files gets deleted.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#158Earlier quoted context omitted.
At this point any damage to the Russian economy translates to Ukranian lives saved.
Really? How do you save lives but deleting the average Dmitry's personal computer files? Maybe they were even working on a popular open source product as many average Russians tend to do. You should re-evaluate your simplistic mindset
To clarify, not refuting your point. Just providing napkin math that I agree it doesn't do much.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#159This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?
I have seen enough war crime photage that I am willing to accept any amount of civilian damage against Russia that is going to have an effect on the war, short of nukes. When your government uses hospital locations as a target list and drop bombs on shelters, I don’t care if your files gets deleted.
You have participated in too many instances of two minutes hate and were gaslighted by propaganda.
I laugh hysterically (in a very sad way), as I scroll through /r/Ukraine and see yet another video headlined as "Another Russian war-crime in Ukraine", that I had already seen few years ago headlined as "Ukrainian war-crime in Donetsk".
There is no truth anymore, literally every man for himself.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#160There is a possibilty that Russia reports that through Interpol Cybercrime or via diplomatic channel, then FBI will have to investigate and possibly lock up Brandon.
Western politicians and public media have been bashing and portraying Russia as "a haven for hackers" for some time now, but it's not like the US is any better from Russian perspective.
Russian law enforcement has huge stacks of unsolved cybercrime cases, that are essentially blocked by lack of cooperation from a foreign counterpart.