Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

61–70 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#61

Earlier quoted context omitted.

Look like they realized the ramification and suddenly changed their payload. Well, that won't help them since companies who uses this module will have their legal department barking. They cannot erase the damage they have done and try to get away of the ramification with version. Since this is distributed through GitHub, Microsoft legal possibly will be involved due to possible violation of cyber/hacking laws in vari…

I don't see any issue for the developers at all. It is their software to create and alter as they see fit. End users choose to use the package, it is not being installed on their machines without their knowledge.

I'm curious if you think the same applies to a developer that writes any kind of ransomware when an end user downloads and installs it knowingly. End user trust is a common attack vector for malware and the developer here took advantage of that just like any other malware developer.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#62

In war, collateral damage, or the harming of non-combatants is usually justified by the argument that it deals significant enough damage to enemy combatants to outweigh the harm done to civilians. What would you call an operation that has nearly 0 effect on enemy combatants and only deals damage to civilians?

Terrorism?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#65

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

Plenty of existing ransomwares delete user files on everything- but -RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".

No post body was provided.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#66
I think a helpful guide is to ask myself: what would admired US and RU astronauts/cosmonauts do?

I imagine that they are scientists, engineers, and colleagues, and will treat each other with support, as people of goodwill.

There are other people who are active combatants right now, whether or not they want to be, and it is tragic beyond words.

I believe that one of the ways that we non-combatants can help is to set an example -- or to leave a door open -- to how we can treat each other when the current conflict is ended.

That doesn't include lashing out angrily and hurting our fellow open source community members, most of whom presumably want no part of the tragedy, and instead want the same things we do (e.g., to develop good software, collaborate and share with others, pursue careers and businesses, support families, etc.).

Re: NPM package compromised by author: erases files on RU / BY computers on install

#68
post #11

I only read it briefly but the HN submission title talks about erasing files on RU/BY computers, while the blog post talks about creating files on desktop. Could someone verify which statement is true?

The analysis here is actually really frustrating. The initial code snippet is only partially analyzed. It makes a HTTP request to a third party geoip service to detect location, then recursively overwrites files if the location is Russia or Belarus. I can't understand why the article doesn't talk about this, but the code is there (albeit obfuscated).

Re: NPM package compromised by author: erases files on RU / BY computers on install

#69
post #67
post #52

This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?

Quoted post unavailable.

Around 15,000 people have been detained for protesting since the start of the war, despite facing 15 years prison sentences for simply calling that war a "war" and russian prisons having documented organized torture rings.

How many times have you faced decades in jail and possible torture?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#70
post #52

This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?

It's been eye opening to see how easily we can normalize this type of stuff. Social media is also full of deranged calls for full on war against Russia (!!), war crime apologia, and just a pervasive hysterical discourse. The slope is getting so slippery that honestly it's got to stop. Let statesmen impose the sanctions that they deem necessary, they know better than random people.

What ukraine needs is advanced weaponry, financial and political support. Not this batshit insane vigilantism that will not end well and do absolutely nothing to hurt the Russian state. I cant even imagine if this happened to a more visible minority, say if China invaded taiwan? It's just scary.

I'm not saying this is on the same level at all, but I'm starting to understand how it got to the point where the internement of Japanese Americans was supported by a majority of Americans back in ww2. As a minority it just gives me this weird unsettling feeling that is a bit hard to explain, even if I'm not russian.

Post reply on HN