Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

71–80 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#71
post #3

Quoted post unavailable.

I rarely visit HN and mostly lurk here, not sure what you're trying to point out. I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on

>This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on

Such precedents should be set, we shouldn't be relying on that chain of trust (as clearly demonstrated here).

Updates should be vetted, signed, etc. Fetching stuff random people push to npm is a recipe for disaster.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#72
post #69
post #67

Earlier quoted context omitted.

Quoted post unavailable.

Around 15,000 people have been detained for protesting since the start of the war, despite facing 15 years prison sentences for simply calling that war a "war" and russian prisons having documented organized torture rings. How many times have you faced decades in jail and possible torture?

[deleted]

Re: NPM package compromised by author: erases files on RU / BY computers on install

#73
post #69
post #67

Earlier quoted context omitted.

Quoted post unavailable.

Around 15,000 people have been detained for protesting since the start of the war, despite facing 15 years prison sentences for simply calling that war a "war" and russian prisons having documented organized torture rings. How many times have you faced decades in jail and possible torture?

No post body was provided.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#74
post #33

Earlier quoted context omitted.

Most countries have cybercrime laws that have clauses for malicious code. Here in Australia for example: Cybercrime offences are found in Commonwealth legislation within parts 10.7 and 10.8 of the Criminal Code Act 1995 and include: -Computer intrusions -Unauthorised modification of data, including destruction of data -Unauthorised impairment of electronic communications, including denial of service attacks -The crea…

Is it unauthorised if a user chooses to add the package themselves? This is not being put into anyone's machine clandestinely. It is the software user's responsibility to ensure the software is doing what you expect.

IANAL, but I suspect that it is considered unauthorized as there are many avenues in which a dependency will get updated without a user specifying this exact package and version. I think the key here is that there is clear malicious intent.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#75
post #67
post #52

This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?

Quoted post unavailable.

I'm sorry but this argument is absurd. Victimizing a population will never make them join your side and especially not when you openly make it clear that you are targeting them. If you followed the internal situation in russia, you'd see that the early opposition to the war vanished after sanctions precisely aimed at civilians started piling up. That's also the difference between actual international sanctions and this type of "activism"; while nation states have the means and the stated objective of specifically hurting the state apparatus and the government of another nation , github repo maintainers literally can only hurt and target normal russian people. Official sanctions will hurt the population too but they at least also target those in power, and those responsible for the war.

Now, obviously, you can say that the russians are themselves the aggressors and should blame their leaders which is totally true. But that doesn't matter because they will absolutely not start supporting the side that is actively trying to punish/victimize them. It's beyond counterproductive and it makes the internal situation much much easier for putin to manage.

By the way, it's scary how how many people are starting to unironically use the same type of argument that bin laden used to attack the US. If you read his letters, he repeatedly said that American civilians were not blameless and complicit to what America was doing to Muslims because they could've changed their government . Worse, they were instead totally supportive of their state's foreign policy! That made them "fair game" as you said. Now if you don't see how dangerous that line of reasoning can be...

Re: NPM package compromised by author: erases files on RU / BY computers on install

#76
post #15

- @vue/cli - @vue/cli-ui - node-ipc@^9.2.1 - @vue/cli-shared-utils - node-ipc@^9.1.1 due to the nature of the ecosystem i feel like - pinning the dependencies - running something like renovate - merging the resulting MR’s with quite a delay from when they were opened as some basic steps in mitigating this sort of silly, but potentially expensive, stuff.

n-1 is a great concept that works right up until log4shell starts happening. The solution is to audit all code you rely on, the unviability of that solution is the fault of the npm micro package ecosystem.

The micro package ecosystem is also self-reinforcing: some micro packages were created by the same developers who have spun ownership of these things into more lucrative positions.

I've tried to get rid of micro packages in the dependency tree of popular libraries, but because it's a turf war, PRs get closed, and the problem continues.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#77
post #73
post #69

Earlier quoted context omitted.

Around 15,000 people have been detained for protesting since the start of the war, despite facing 15 years prison sentences for simply calling that war a "war" and russian prisons having documented organized torture rings. How many times have you faced decades in jail and possible torture?

Quoted post unavailable.

In London, in 2002, there were big protests against the imminent war in Iraq. According to Wikipedia, "an anti-war rally in London drew a crowd of at least 150,000". The UK is, nominally at least, a democracy. It's certainly a place where protesters are at much less risk than protesters in Russia. But after the protests we still invaded Iraq.

I support Ukraine 100%. I'm glad the UK and EU and US are sending weapons and aid. I'm glad that some Russians are vocally against the war. But honestly I don't know what people expect the Russian protests to accomplish. I don't know how big would be "too big to ignore" - it doesn't seem possible.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#78
post #73
post #69

Earlier quoted context omitted.

Around 15,000 people have been detained for protesting since the start of the war, despite facing 15 years prison sentences for simply calling that war a "war" and russian prisons having documented organized torture rings. How many times have you faced decades in jail and possible torture?

Quoted post unavailable.

You do understand you are talking about real people? Young girls, parents of toddlers, grandmas? Why do you think _you_ have the right to tell them to go face possible death and torture?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#79

Earlier quoted context omitted.

n-1 is a great concept that works right up until log4shell starts happening. The solution is to audit all code you rely on, the unviability of that solution is the fault of the npm micro package ecosystem.

The micro package ecosystem is also self-reinforcing: some micro packages were created by the same developers who have spun ownership of these things into more lucrative positions. I've tried to get rid of micro packages in the dependency tree of popular libraries, but because it's a turf war, PRs get closed, and the problem continues.

I don’t think anything will change until large development firms pressurise popular projects to stop the behaviour.

I hope you speak with executive and lead developers to highlight the volatility of the ecosystem, like I do, every chance I get.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#80
I love the idea we will soon have western and eastern open source projects. Even if internet isn't bifurcated, both sides will be too paranoid to install software from the other side. All software projects will have to pedantically vet every line of a commit, photo ID every contributor, to avoid subtle bugs intentionally committed and sent to millions.

Why stop at countries? How hard would it be to use ML to detect if the user has the wrong politics? Why stop at just deleting files? How about downloading as much illegal content as possible, sending embarrassing emails, etc? There's so many possibilities here.

Post reply on HN