Earlier quoted context omitted.
> I don't know how I feel about this. > One hand, this is a seemingly non-violent and subtle way to protest. You can't be serious. Being non-violent and subtle is no excuse for deliberately making software have real side effects on a computer that it's not advertised to do, especially a node library. Node modules for some reason tend to be very small and have trivial tasks like checking if something is a number. Imag…
I dunno. If you’re sloppy enough to install whatever dependencies onto your system, and not notice a new dependency, called “peacenotwar”, I’d say it’s your problem. Doesn’t necessarily make it OK, but this will only affect the sloppy.
NPM package compromised by author: erases files on RU / BY computers on install
31–40 of 188 posts
Re: NPM package compromised by author: erases files on RU / BY computers on install
#32I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…
I would imagine web developers over there, being more educated, technical, and exposed to the West, would be the ones less likely to support the war.
There's nothing subtle about wiping files, why not provide news and information that's being blocked? This could have been an information bridge that would be hard to censor. Hell, run a crypto miner on their machine and donate to Ukraine if you're trying help, that'll have more of an impact then wiping some poor dev's files.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#33Earlier quoted context omitted.
There's no reason to excuse criminals over lack of enforcement.
So he’s a criminal now? Under what law, of what nation? Russia?
Cybercrime offences are found in Commonwealth legislation within parts 10.7 and 10.8 of the Criminal Code Act 1995 and include:
-Computer intrusions
-Unauthorised modification of data, including destruction of data
-Unauthorised impairment of electronic communications, including denial of service attacks
-The creation and distribution of malicious software (for example, malware, viruses, ransomware)
-Dishonestly obtaining or dealing in personal financial information.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#34I only read it briefly but the HN submission title talks about erasing files on RU/BY computers, while the blog post talks about creating files on desktop. Could someone verify which statement is true?
> On March 8, at 7:25PM GMT+2 and less than four hours after node-ipc@10.1.3 had been published to roll back the destructive payload, a new major version node-ipc@11.0.0 was released on the npmjs registry. The old version erased files, the new one leaves a file on the desktop.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#35Re: NPM package compromised by author: erases files on RU / BY computers on install
#36Earlier quoted context omitted.
> On March 8, at 7:25PM GMT+2 and less than four hours after node-ipc@10.1.3 had been published to roll back the destructive payload, a new major version node-ipc@11.0.0 was released on the npmjs registry. The old version erased files, the new one leaves a file on the desktop.
Look like they realized the ramification and suddenly changed their payload. Well, that won't help them since companies who uses this module will have their legal department barking. They cannot erase the damage they have done and try to get away of the ramification with version. Since this is distributed through GitHub, Microsoft legal possibly will be involved due to possible violation of cyber/hacking laws in vari…
Re: NPM package compromised by author: erases files on RU / BY computers on install
#37I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…
> I don't know how I feel about this. > One hand, this is a seemingly non-violent and subtle way to protest. You can't be serious. Being non-violent and subtle is no excuse for deliberately making software have real side effects on a computer that it's not advertised to do, especially a node library. Node modules for some reason tend to be very small and have trivial tasks like checking if something is a number. Imag…
Then people could write their own code to check if something is a number.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#38Re: NPM package compromised by author: erases files on RU / BY computers on install
#39Earlier quoted context omitted.
So he’s a criminal now? Under what law, of what nation? Russia?
Most countries have cybercrime laws that have clauses for malicious code. Here in Australia for example: Cybercrime offences are found in Commonwealth legislation within parts 10.7 and 10.8 of the Criminal Code Act 1995 and include: -Computer intrusions -Unauthorised modification of data, including destruction of data -Unauthorised impairment of electronic communications, including denial of service attacks -The crea…
Re: NPM package compromised by author: erases files on RU / BY computers on install
#40- @vue/cli - @vue/cli-ui - node-ipc@^9.2.1 - @vue/cli-shared-utils - node-ipc@^9.1.1 due to the nature of the ecosystem i feel like - pinning the dependencies - running something like renovate - merging the resulting MR’s with quite a delay from when they were opened as some basic steps in mitigating this sort of silly, but potentially expensive, stuff.
The mistake was fixed within 6 minutes: https://github.com/vuejs/vue-cli/commit/b0d931668e7e8450a285...
It looks like the malware version of @vue/cli has been downloaded a total of 170 times.[1] That's 0.13% of all downloads of that package this week. It's also important to note that @vue/cli has been deprecated for months. If you're making a new Vue project today[2] you'll use create-vue[3] which doesn't depend on node-ipc at all.
1. https://www.npmjs.com/package/@vue/cli?activeTab=versions