Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

21–30 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#21
post #8

Guy has his real name on his github page. Googled him, he has a Wikipedia page, created by a Wikipedia user with the same username as his Github one. Well, I think that says all I need to know about his character.

This developer has every right to a nervous breakdown over the war in Ukraine.

The npm ecosystem distributing yet another malicious module is more serious though.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#22

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

Plenty of existing ransomwares delete user files on everything- but -RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".

"Some people in my country were victimized by organized crime in another country, so it's turnabout, and hence fair play, for me to victimize other people in that country"?

"Some people in my country were victimized by organized crime in another country, and that country's government didn't try to stop the criminal activity, so it's turnabout, and hence fair play, for me to victimize other people in that country"?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#23
post #21
post #8

Guy has his real name on his github page. Googled him, he has a Wikipedia page, created by a Wikipedia user with the same username as his Github one. Well, I think that says all I need to know about his character.

This developer has every right to a nervous breakdown over the war in Ukraine. The npm ecosystem distributing yet another malicious module is more serious though.

There's no reason to excuse criminals over lack of enforcement.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#25
post #23
post #21

Earlier quoted context omitted.

This developer has every right to a nervous breakdown over the war in Ukraine. The npm ecosystem distributing yet another malicious module is more serious though.

There's no reason to excuse criminals over lack of enforcement.

So he’s a criminal now? Under what law, of what nation? Russia?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#26
Honestly a very harmful sort of "doing something about it". As if deleting someone's (presumably, normal people) files will make them more understanding of the difficulties in the ongoing conflict. Lying about it is also petty, as seen below. Malicious software is malicious regardless of any intentions and should be prosecuted as such. And if one really feels obliged to make their part as they wish, there's many examples of relatively harmless ways to do so, for example Notepad++ used to open a new tab with text inside, that is not particularly harmful.

>It is documented what it does and only writes a file if it does not exist. You are free to lock your dependency to a version that does not include this until something happens with the war, like it turns into WWIII and more of us wish that we had done something about it, or ends and this gets removed.

from https://github.com/RIAEvangelist/node-ipc/issues/233#issueco...

Re: NPM package compromised by author: erases files on RU / BY computers on install

#27
post #19
post #5

I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…

> I don't know how I feel about this. > One hand, this is a seemingly non-violent and subtle way to protest. You can't be serious. Being non-violent and subtle is no excuse for deliberately making software have real side effects on a computer that it's not advertised to do, especially a node library. Node modules for some reason tend to be very small and have trivial tasks like checking if something is a number. Imag…

I dunno. If you’re sloppy enough to install whatever dependencies onto your system, and not notice a new dependency, called “peacenotwar”, I’d say it’s your problem.

Doesn’t necessarily make it OK, but this will only affect the sloppy.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#28
post #22

Earlier quoted context omitted.

Plenty of existing ransomwares delete user files on everything- but -RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".

"Some people in my country were victimized by organized crime in another country, so it's turnabout, and hence fair play, for me to victimize other people in that country"? "Some people in my country were victimized by organized crime in another country, and that country's government didn't try to stop the criminal activity, so it's turnabout, and hence fair play, for me to victimize other people in that country"?

No post body was provided.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#29
post #10
post #7

Earlier quoted context omitted.

it isn't going to stop Putin but it could negatively impact normal people. in no universe will the handful of Russian programmers impacted by this rise up and overthrow their government. but they will be forced to work extra hours cleaning up any damage this caused to their system. This is really lame virtue signalling that only harms fellow workers because their government is terrible.

But this is pretty much the exact logic sanctions work by. Putin and his cronies might lose some super yachts but the main aim is to crash the Russian economy, which will hurt everyday Russians far more than any leader. Not that I have any better ideas, but you could argue this move is in a similar vein.

The sanctions also choke the state's military of funding.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#30
post #23

Earlier quoted context omitted.

There's no reason to excuse criminals over lack of enforcement.

So he’s a criminal now? Under what law, of what nation? Russia?

Wikipedia TOS
Post reply on HN