Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

41–50 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#41
post #33

Earlier quoted context omitted.

Most countries have cybercrime laws that have clauses for malicious code. Here in Australia for example: Cybercrime offences are found in Commonwealth legislation within parts 10.7 and 10.8 of the Criminal Code Act 1995 and include: -Computer intrusions -Unauthorised modification of data, including destruction of data -Unauthorised impairment of electronic communications, including denial of service attacks -The crea…

Is it unauthorised if a user chooses to add the package themselves? This is not being put into anyone's machine clandestinely. It is the software user's responsibility to ensure the software is doing what you expect.

Upto a court to decide. Turns out he's in California which has laws against writing and distributing malicious code.

He's looking at state level:

if charged as a misdemeanor, the crime is punishable by: imprisonment in county jail for up to one year, and/or a maximum fine of $5,000.6

If charged as a felony, the offense is punishable by: imprisonment for up to three years, and/or a maximum fine of $10,000.7

Federal charges I'm not sure about.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#42

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

Plenty of existing ransomwares delete user files on everything- but -RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".

But that shouldn't be an excuse to sink to their level.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#44

Earlier quoted context omitted.

Look like they realized the ramification and suddenly changed their payload. Well, that won't help them since companies who uses this module will have their legal department barking. They cannot erase the damage they have done and try to get away of the ramification with version. Since this is distributed through GitHub, Microsoft legal possibly will be involved due to possible violation of cyber/hacking laws in vari…

I don't see any issue for the developers at all. It is their software to create and alter as they see fit. End users choose to use the package, it is not being installed on their machines without their knowledge.

Four things:

1) Why they changed the code all of the sudden? If they are fine with realeasing this kind of damaging payoad, then why they decided to change the code? I mean they want to make a statement, right? Then they should leave the original code and stand by it. Why they are not standing by their statement?

2) Why RIAEvangelist editing people comments to minimize their languages? why they are censoring their comments? I checked the edited button and you can see RIAEvangelist made some interesting changes on their comments.

3) If RIAEvangelist felt his protest should be public and known, but users can't? You can clearly see they are trying to censoring comments and users at the beginning. So odd for developer who want to protest but yet refused to allow users to voice their protest. Strange strange mentality.

4) That is their free speech but that is only free speech from the governments. I realize my comment indicate about legal ramification. It is not the governments that RIAEvangelist should worry about, it is the private companies they should worry about, espically the platform they are using are known to be extremely litigious. They have far more power and money to ensure their maximum punishment. Private companies will use the law and lead hard on the government to do something. Private companies have done it before and they will do it again.

I don't have a issue with their principle. It just it is not the right platform/soapbox to use because it can cause unexpected damage if the original code is left up. It could spill to over companies who would be unintentionally targeted by it. Software is never perfect and it can be ugly. The developer have the right mind to change the code to minimize the damage because it will be ugly for them if they leave it up.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#45
post #41

Earlier quoted context omitted.

Is it unauthorised if a user chooses to add the package themselves? This is not being put into anyone's machine clandestinely. It is the software user's responsibility to ensure the software is doing what you expect.

Upto a court to decide. Turns out he's in California which has laws against writing and distributing malicious code. He's looking at state level: if charged as a misdemeanor, the crime is punishable by: imprisonment in county jail for up to one year, and/or a maximum fine of $5,000.6 If charged as a felony, the offense is punishable by: imprisonment for up to three years, and/or a maximum fine of $10,000.7 Federal ch…

Whats up with the .6 and .7?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#46

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

Plenty of existing ransomwares delete user files on everything- but -RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".

But whatabout the other guys????

Are you a child?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#47

It's his software, he can do what he wants with it. It is the responsibility of those who use packages to determine what it is doing. Everyone is free to write their own version or even fork an earlier version of the code if they want.

t. malware writer

Re: NPM package compromised by author: erases files on RU / BY computers on install

#48

Earlier quoted context omitted.

Plenty of existing ransomwares delete user files on everything- but -RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".

But whatabout the other guys???? Are you a child?

Good question, you should ask the maintainer that. I'm speculating about their possible motive for abusing the FLOSS ecosystem in such a destructive way, not trying to justify their behavior or anything.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#49
In war, collateral damage, or the harming of non-combatants is usually justified by the argument that it deals significant enough damage to enemy combatants to outweigh the harm done to civilians.

What would you call an operation that has nearly 0 effect on enemy combatants and only deals damage to civilians?

Post reply on HN