Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

51–60 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#55
post #52

This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?

On top of that, petty, personal attacks like that have the absolute opposite effect if the supposed intention is to motivate russians to protest. It just makes people angry and suspicious of the west, nothing else.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#57
post #26

Honestly a very harmful sort of "doing something about it". As if deleting someone's (presumably, normal people) files will make them more understanding of the difficulties in the ongoing conflict. Lying about it is also petty, as seen below. Malicious software is malicious regardless of any intentions and should be prosecuted as such. And if one really feels obliged to make their part as they wish, there's many exam…

No post body was provided.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#58
post #10
post #7

Earlier quoted context omitted.

it isn't going to stop Putin but it could negatively impact normal people. in no universe will the handful of Russian programmers impacted by this rise up and overthrow their government. but they will be forced to work extra hours cleaning up any damage this caused to their system. This is really lame virtue signalling that only harms fellow workers because their government is terrible.

But this is pretty much the exact logic sanctions work by. Putin and his cronies might lose some super yachts but the main aim is to crash the Russian economy, which will hurt everyday Russians far more than any leader. Not that I have any better ideas, but you could argue this move is in a similar vein.

Sanctions lower taxes which hurt the government funding. It may or may not be effective but they are not remotely the same.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#59
post #45
post #41

Earlier quoted context omitted.

Upto a court to decide. Turns out he's in California which has laws against writing and distributing malicious code. He's looking at state level: if charged as a misdemeanor, the crime is punishable by: imprisonment in county jail for up to one year, and/or a maximum fine of $5,000.6 If charged as a felony, the offense is punishable by: imprisonment for up to three years, and/or a maximum fine of $10,000.7 Federal ch…

Whats up with the .6 and .7?

Probably section numbers that copied and pasted weirdly.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#60
post #33

Earlier quoted context omitted.

Most countries have cybercrime laws that have clauses for malicious code. Here in Australia for example: Cybercrime offences are found in Commonwealth legislation within parts 10.7 and 10.8 of the Criminal Code Act 1995 and include: -Computer intrusions -Unauthorised modification of data, including destruction of data -Unauthorised impairment of electronic communications, including denial of service attacks -The crea…

Is it unauthorised if a user chooses to add the package themselves? This is not being put into anyone's machine clandestinely. It is the software user's responsibility to ensure the software is doing what you expect.

I rather doubt grandma pressing OK when asked to install the CoolWebSearch toolbar would hold up as a legal defense.
Post reply on HN