Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

181–188 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#181
post #81

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

I'm two days late but this is an argument for a developer not removing a security vulnerability from a dead project they've stopped maintaining, not this. I feel like not actively choosing to push malware to a repository where you know many, many automated systems will pull that malware onto the systems of your end-users due to a poor security model in the ecosystem you're developing in is a very very low bar of obligation as a maintainer.

Like, okay, you can't expect a doctor to save the life of every person who comes into the ER, but you can hopefully expect them not to start stabbing patients to death, and something should probably happen if they do, right?

Your argument makes sense for inaction (and is important and not brought up enough, honestly; there is a lot of entitlement in the open source world and people treat library developers in some pretty nasty ways), but not for action, as is the case here. The only obligation anyone expected here was the obligation to hold yourself back from making your project that gets millions of downloads per week point to malware.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#182
post #152

Earlier quoted context omitted.

Plenty of existing ransomwares delete user files on everything- but -RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".

Quoted post unavailable.

You know, if you really want to post like you're on /g/ you can just go back to /g/. It's still there.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#183
post #181
post #81

Earlier quoted context omitted.

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

I'm two days late but this is an argument for a developer not removing a security vulnerability from a dead project they've stopped maintaining, not this. I feel like not actively choosing to push malware to a repository where you know many, many automated systems will pull that malware onto the systems of your end-users due to a poor security model in the ecosystem you're developing in is a very very low bar of obli…

I agree, I think I misread.

If you actively distribute, as in push your code out to the world via pushing it into npm, that's very different to sharing the code on GitHub.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#184
post #81

Earlier quoted context omitted.

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

> If they want to publish their upstream as malware, okay. NPM's terms explicitly disallow malware. They're free to put the raw source on say GitHub, but the author isn't permitted to package and distribute it on NPM. https://docs.npmjs.com/policies/open-source-terms

You're spot on, my mistake.

I thought the author published it via Git and some npm maintainer scraped them.

If they distributed this code to end users that's just a cyberattack.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#185
post #81

Earlier quoted context omitted.

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

>If they want to publish their upstream as malware, okay. I think you'll find that argument will not be very persuasive to a judge if the case is that the author of the software knowingly adds code in after people have integrated it into their systems that on purpose damages those systems. Intention will often carry weight, and no claiming of rights and purity and see I wrote here you can't do anything to me! is goin…

Agree with this.

I think the difference is between sharing the code and pushing dodgy code down into npm. Which is my misunderstanding.

Pushing this dodgy code down to end users in Russia/Ukraine is a cyberattack.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#187
post #186
post #182

Earlier quoted context omitted.

You know, if you really want to post like you're on /g/ you can just go back to /g/. It's still there.

Quoted post unavailable.

I'm just saying you'd be happier there, it even has boards for non-tech-related stuff since you don't post here about tech-related stuff. Perfect fit!

Re: NPM package compromised by author: erases files on RU / BY computers on install

#188
post #187
post #186

Earlier quoted context omitted.

Quoted post unavailable.

I'm just saying you'd be happier there, it even has boards for non-tech-related stuff since you don't post here about tech-related stuff. Perfect fit!

>I'm just saying you'd be happier there

You'd be happier on /r/cuckold, yet here you are.

>it even has boards for non-tech-related stuff since you don't post here about tech-related stuff.

I posted on a thread about malware, and made a comment about malware. That's "tech-related stuff". You have poor reading comprehension.

>Perfect fit!

Reddit also has /r/soyboy as well! Perfect fit!

Post reply on HN