34 ms·
NPM package compromised by author: erases files on RU / BY computers on install
- toomuchtodo 5y ago
- asn007 5y agoI rarely visit HN and mostly lurk here, not sure what you're trying to point out. I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on
- toomuchtodo 5y agoI wasn’t suggesting any nefarious intent, only that this was the topic that made you go “Today is the day I post.” Sorry to hear you were impacted by this. Software supply chain challenges are copious, unwieldy, and everywhere.
- TMWNN 5y ago>I wasn’t suggesting any nefarious intent, Oh, please. The only thing missing was to accuse asn007 of being a "Russian troll", although I suppose you realized that that would not be appropriate in this case. Just own up to your apology.
- toomuchtodo 5y agoSorry that’s what you took from it, if you’re looking for an apology. People are interesting, that’s all, and I am curious about how they tick. There is a difference between “How odd!” and “This person is up to no good.” Whether someone is a “Russian troll” or not really doesn’t concern me, and I wouldn’t call someone out if I thought they were (that’s a mod’s problem and poor form), nor was that what I was insinuating.
- totony 5y ago>This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on Such precedents should be set, we shouldn't be relying on that chain of trust (as clearly demonstrated here). Updates should be vetted, signed, etc. Fetching stuff random people push to npm is a recipe for disaster.
- gtirloni 5y agoHow are regular developers going to vet the literally 1000s of Node.js dependencies they rely on? And who's signing these updates? The package owner? Well, he's the one adding malicious code so he can sign whatever he wants. I'll say it again, Node.js needs a proper standard library like Go that takes care of common needs most people have. It's been improving but it was a historical mistake to let microdependencies run wild.
- gkbrk 5y ago> How are regular developers going to vet the literally 1000s of Node.js dependencies they rely on? Perhaps they shouldn't be relying on thousands of NPM packages. It's not difficult to write JS code that doesn't `npm install` the entire package ecosystem.
- gtirloni 5y agoIf you use React, Vue and others, that decision has been made for you.
- totony 5y agoIMO npm should have a "stable repo" and a "community repo" just like most distribution packagers have had for a long time.
- btreecat 5y agoI don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container running with root permissions.
- yesbut 5y agoit isn't going to stop Putin but it could negatively impact normal people. in no universe will the handful of Russian programmers impacted by this rise up and overthrow their government. but they will be forced to work extra hours cleaning up any damage this caused to their system. This is really lame virtue signalling that only harms fellow workers because their government is terrible.
- afavour 5y agoBut this is pretty much the exact logic sanctions work by. Putin and his cronies might lose some super yachts but the main aim is to crash the Russian economy, which will hurt everyday Russians far more than any leader. Not that I have any better ideas, but you could argue this move is in a similar vein.
- btreecat 5y agoSo sanctions? I get it, collateral damage is indeed collateral. That's why I don't know how to feel. If this move broke some key software used on the battlefield, would we all be so quick with our positions?
- chizhik-pyzhik 5y agoRegardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233 https://github.com/RIAEvangelist/node-ipc/issues/233
- paxys 5y agoYup. Although if you do want to get political, I'd say this falls under the definition of cyber warfare. Also the maintainer didn't only "allow" it, it seems he is the author of the malicious module as well.
- quinnjh 5y agoWhats painful is that in terms of cyberwarfare, allied systems maintain dominance of global grid with innovation and open source. If we had allies in russia, im sure we have fewer now. This sort of DOS attack is effective in first order effects but the second order effects could be increased resentment and new systems developed in isolation.
- zozbot234 5y agoPlenty of existing ransomwares delete user files on everything-but-RU machines. Perhaps the maintainer of this package subscribes to the old view that "turnabout is fair play".
- schoen 5y ago"Some people in my country were victimized by organized crime in another country, so it's turnabout, and hence fair play, for me to victimize other people in that country"? "Some people in my country were victimized by organized crime in another country, and that country's government didn't try to stop the criminal activity, so it's turnabout, and hence fair play, for me to victimize other people in that country"?
- madaxe_again 5y ago
- netsharc 5y agoGuy has his real name on his github page. Googled him, he has a Wikipedia page, created by a Wikipedia user with the same username as his Github one. Well, I think that says all I need to know about his character.
- markvdb 5y agoThis developer has every right to a nervous breakdown over the war in Ukraine. The npm ecosystem distributing yet another malicious module is more serious though.
- rsstack 5y agoThere's no reason to excuse criminals over lack of enforcement.
- madaxe_again 5y agoSo he’s a criminal now? Under what law, of what nation? Russia?
- kevin_thibedeau 5y agoWikipedia TOS
- sva_ 5y agoCriminal because of violating Wikipedia TOS. Seems about right. /s
- jaimex2 5y agoMost countries have cybercrime laws that have clauses for malicious code. Here in Australia for example: Cybercrime offences are found in Commonwealth legislation within parts 10.7 and 10.8 of the Criminal Code Act 1995 and include: -Computer intrusions -Unauthorised modification of data, including destruction of data -Unauthorised impairment of electronic communications, including denial of service attacks -The creation and distribution of malicious software (for example, malware, viruses, ransomware) -Dishonestly obtaining or dealing in personal financial information.
- jakub_g 5y agoI only read it briefly but the HN submission title talks about erasing files on RU/BY computers, while the blog post talks about creating files on desktop. Could someone verify which statement is true?
- lights0123 5y ago> On March 8, at 7:25PM GMT+2 and less than four hours after node-ipc@10.1.3 had been published to roll back the destructive payload, a new major version node-ipc@11.0.0 was released on the npmjs registry. The old version erased files, the new one leaves a file on the desktop.
- Isthatablackgsd 5y agoLook like they realized the ramification and suddenly changed their payload. Well, that won't help them since companies who uses this module will have their legal department barking. They cannot erase the damage they have done and try to get away of the ramification with version. Since this is distributed through GitHub, Microsoft legal possibly will be involved due to possible violation of cyber/hacking laws in various countries. This is going to be ugly for the developers.
- celticninja 5y agoI don't see any issue for the developers at all. It is their software to create and alter as they see fit. End users choose to use the package, it is not being installed on their machines without their knowledge.
- planetree 5y agoMust GPL my ransomware. Thanks for the reminder!
- Isthatablackgsd 5y agoFour things: 1) Why they changed the code all of the sudden? If they are fine with realeasing this kind of damaging payoad, then why they decided to change the code? I mean they want to make a statement, right? Then they should leave the original code and stand by it. Why they are not standing by their statement? 2) Why RIAEvangelist editing people comments to minimize their languages? why they are censoring their comments? I checked the edited button and you can see RIAEvangelist made some interesting changes on their comments. 3) If RIAEvangelist felt his protest should be public and known, but users can't? You can clearly see they are trying to censoring comments and users at the beginning. So odd for developer who want to protest but yet refused to allow users to voice their protest. Strange strange mentality. 4) That is their free speech but that is only free speech from the governments. I realize my comment indicate about legal ramification. It is not the governments that RIAEvangelist should worry about, it is the private companies they should worry about, espically the platform they are using are known to be extremely litigious. They have far more power and money to ensure their maximum punishment. Private companies will use the law and lead hard on the government to do something. Private companies have done it before and they will do it again. I don't have a issue with their principle. It just it is not the right platform/soapbox to use because it can cause unexpected damage if the original code is left up. It could spill to over companies who would be unintentionally targeted by it. Software is never perfect and it can be ugly. The developer have the right mind to change the code to minimize the damage because it will be ugly for them if they leave it up.
- superasn 5y agoGuess it's time to chroot each project folder if you're using any package manager or external libraries. Though on second thought it's just a band aid as the damage which can be done after deployment is far worse than anything before.
- kmlx 5y ago- @vue/cli - @vue/cli-ui - node-ipc@^9.2.1 - @vue/cli-shared-utils - node-ipc@^9.1.1 due to the nature of the ecosystem i feel like - pinning the dependencies - running something like renovate - merging the resulting MR’s with quite a delay from when they were opened as some basic steps in mitigating this sort of silly, but potentially expensive, stuff.
- hsbauauvhabzb 5y agon-1 is a great concept that works right up until log4shell starts happening. The solution is to audit all code you rely on, the unviability of that solution is the fault of the npm micro package ecosystem.
- mac-chaffee 5y agoThe micro package ecosystem is also self-reinforcing: some micro packages were created by the same developers who have spun ownership of these things into more lucrative positions. I've tried to get rid of micro packages in the dependency tree of popular libraries, but because it's a turf war, PRs get closed, and the problem continues.
- hsbauauvhabzb 5y agoI don’t think anything will change until large development firms pressurise popular projects to stop the behaviour. I hope you speak with executive and lead developers to highlight the volatility of the ecosystem, like I do, every chance I get.
- gtirloni 5y agoNode.js just needs a proper standard library and this will stop in no time. Never going to happen though.
- hsbauauvhabzb 5y ago
- tag2103 5y agoThis is a direct violation of the trust developers place in open source and does nothing to advance any individual's politics. This is purely malicious.
- 0x_rs 5y agoHonestly a very harmful sort of "doing something about it". As if deleting someone's (presumably, normal people) files will make them more understanding of the difficulties in the ongoing conflict. Lying about it is also petty, as seen below. Malicious software is malicious regardless of any intentions and should be prosecuted as such. And if one really feels obliged to make their part as they wish, there's many examples of relatively harmless ways to do so, for example Notepad++ used to open a new tab with text inside, that is not particularly harmful. >It is documented what it does and only writes a file if it does not exist. You are free to lock your dependency to a version that does not include this until something happens with the war, like it turns into WWIII and more of us wish that we had done something about it, or ends and this gets removed. from https://github.com/RIAEvangelist/node-ipc/issues/233#issuecomment-1063557929 https://github.com/RIAEvangelist/node-ipc/issues/233#issueco...
- unsupp0rted 5y ago
- QuadmasterXLII 5y agoAt this point any damage to the Russian economy translates to Ukranian lives saved.
- ddaalluu2 5y agoReally? How do you save lives but deleting the average Dmitry's personal computer files? Maybe they were even working on a popular open source product as many average Russians tend to do. You should re-evaluate your simplistic mindset
- beeboop 5y agoCausing tens or hundreds of thousands of wasted hours by (relatively) high-earning software developers in Russia (who average about 20k USD a year, or $11/hour) is only, generously, a few million dollars USD in "damages". To clarify, not refuting your point. Just providing napkin math that I agree it doesn't do much.
- celticninja 5y agoIt's his software, he can do what he wants with it. It is the responsibility of those who use packages to determine what it is doing. Everyone is free to write their own version or even fork an earlier version of the code if they want.
- Jimbonius 5y agot. malware writer
- tengbretson 5y agoIn war, collateral damage, or the harming of non-combatants is usually justified by the argument that it deals significant enough damage to enemy combatants to outweigh the harm done to civilians. What would you call an operation that has nearly 0 effect on enemy combatants and only deals damage to civilians?
- Bolkan 5y agoTerrorism?
- adamrezich 5y agoslacktivism
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- slim 5y agoThis is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?
- deleted 5y ago[deleted]
- asats 5y agoOn top of that, petty, personal attacks like that have the absolute opposite effect if the supposed intention is to motivate russians to protest. It just makes people angry and suspicious of the west, nothing else.
- tiahura 5y ago
- jddil 5y ago
- asats 5y agoAround 15,000 people have been detained for protesting since the start of the war, despite facing 15 years prison sentences for simply calling that war a "war" and russian prisons having documented organized torture rings. How many times have you faced decades in jail and possible torture?
- deleted 5y ago[deleted]
- jddil 5y ago
- azornathogron 5y agoIn London, in 2002, there were big protests against the imminent war in Iraq. According to Wikipedia, "an anti-war rally in London drew a crowd of at least 150,000". The UK is, nominally at least, a democracy. It's certainly a place where protesters are at much less risk than protesters in Russia. But after the protests we still invaded Iraq. I support Ukraine 100%. I'm glad the UK and EU and US are sending weapons and aid. I'm glad that some Russians are vocally against the war. But honestly I don't know what people expect the Russian protests to accomplish. I don't know how big would be "too big to ignore" - it doesn't seem possible.
- RoddaWallPro 5y agoNever a better time to be vendoring your npm deps & reviewing the updates to packages. Not too difficult to pull in the new version, then git diff the changes in the `lib` directory of that package.
- lamontcg 5y ago"you get what you pay for"
- TrevorJ 5y agoKind of a thoughtless comment from an industry that owes so much to the open source community.
- Bolkan 5y agoBut muh security patches!!!!!!
- neilv 5y agoI think a helpful guide is to ask myself: what would admired US and RU astronauts/cosmonauts do? I imagine that they are scientists, engineers, and colleagues, and will treat each other with support, as people of goodwill. There are other people who are active combatants right now, whether or not they want to be, and it is tragic beyond words. I believe that one of the ways that we non-combatants can help is to set an example -- or to leave a door open -- to how we can treat each other when the current conflict is ended. That doesn't include lashing out angrily and hurting our fellow open source community members, most of whom presumably want no part of the tragedy, and instead want the same things we do (e.g., to develop good software, collaborate and share with others, pursue careers and businesses, support families, etc.).
- deleted 5y ago[deleted]
- kelnos 5y agoThis is the sad thing about all of this. Many people are demonizing average Russian citizens for the actions of their government. When the US invaded Iraq in 2003, I was very much against it, but felt powerless to change the course of my government. (And the US government kept on doing what it felt like, no matter how unjust its actions.) While I was ashamed of my country's actions, I didn't think it would be fair for people in other countries to punish me personally for them. And this is in the US, a supposed liberal democracy! What chance does your average Russian citizen have of getting a dictator like Putin to change his mind here?
- naugtur 5y agoI agree with the sentiment here. Theoretically though in representative democracy you choose the government to represent you and be an agent for making your decisions. You are responsible for what your government does in part that equals 1/Population
- slim 5y agoeverybody knows that representative democracy is not representative. so, no, even theoretically you're not responsible for that reason. although you may be responsible for not doing anything to put in place a more representative democracy in your country (ie. be more involved in politics)
- Houshalter 5y agoI love the idea we will soon have western and eastern open source projects. Even if internet isn't bifurcated, both sides will be too paranoid to install software from the other side. All software projects will have to pedantically vet every line of a commit, photo ID every contributor, to avoid subtle bugs intentionally committed and sent to millions. Why stop at countries? How hard would it be to use ML to detect if the user has the wrong politics? Why stop at just deleting files? How about downloading as much illegal content as possible, sending embarrassing emails, etc? There's so many possibilities here.
- octoberfranklin 5y ago> photo ID every contributor If the Western FOSS ecosystem demands KYC from me I'm dumping them for the Non-Aligned Movement.
- JonChesterfield 5y agoComments seem split between "that's illegal, beware the lawyers" and "don't RCE yourself then cry about it". I've got some bash scripts on GitHub that would delete files on the local machine if run. Today I don't care if anyone else runs them. If however the winds are blowing towards people doing themselves harm with my code is my problem, I guess I should delete the code I've published. Bad precedent to see here.
- encryptluks2 5y agoBig difference between random code on GitHub and modifying a high-use JS dependency to delete user files. I'm not against protesting in software, for example printing something to stdout during install, but deleting files is malicious beyond reprieve.
- JonChesterfield 5y agoMaybe, I'm not totally confident about there being a meaningful difference. If the former counts as distributing malware, my bash script that clobbers local directories to put the machine back into a sane default state might be too. It does rm -rf ~/$DIR and similar. It's just not as successfully deployed. Or software that wastes resources, maybe it goes into an infinite loop and DoS the local CPU. I've got one of those called 'heater' or similar that I used to warm up a macbook in a cold office. If someone ran that on cluster it would be unhelpful. Maybe the change in functionality to malware from a widely shipped useful product is the key distinction, coupled with limited disclosure of the behaviour change.
- Legogris 5y agoThere is a proposal to add OCaps on a language level in TC39[0]. There is a drop-in implementation which already works in both Nodejs and browsers[1]. As a developer who wants to sandbox your own (recursive) dependencies, this is wrapped and made accessible today in Lavamoat[2]. Basically a package or app can provide a policy manifest specifying which capabilities (e.g. network or filesystem access) should be granted for each sandboxed dependency. Also comes with a tool that will auto-generate a starting point from your existing dependency tree. IMO this is the future. Currently Lavamoat does come with a performance penalty but hopefully this idea will catch on and make it into language runtime implementations. Lavamoat is still marked as "preprod" on npm but talking to the original author, the API is practically stable and it will shortly have its first stable release. [0]: https://github.com/tc39/proposal-ses https://github.com/tc39/proposal-ses [1]: https://github.com/endojs/endo/tree/master/packages/ses https://github.com/endojs/endo/tree/master/packages/ses [2]: https://github.com/LavaMoat/LavaMoat https://github.com/LavaMoat/LavaMoat
- m1keil 5y ago“Trust takes years to build, seconds to break, and forever to repair”.
- jeroenhd 5y agoThis seems like a rather silly form of protest. Delete people's files and the only thing you're creating here is more hatred directed at yourself. If you want to sabotage all Russians for some weird reason, just introduce a race condition that's masqueraded as a compatibility fix for the Russian locale. If you want to send out a message, take a more peaceful approach. Create file or print out a translated message like "<Citizen name>, age <age>, was killed in the illegal Russian invasion of Ukraine on <date>" in Russian. Add a link to a picture or a news article if you want. Still a pretty annoying move, probably universally considered in bad taste by most people, but not illegal or destructive. Add something like "the economic recession is because the Western world opposes the Russian government" to make that clear as well, because the immense inflation will probably hit random citizens hardest. Best case scenario you're informing some ignorant Russians stuck behind state propaganda, worst case scenario you piss off some Russian nationalists who will stop using your library. In the end, this is just another demonstration of how dangerous modern dependency management is. NPM has been through leftpad, colors, now node-ipc, and there's still no way to prevent it from happening again. I don't know of any language ecosystem with a package manager that doesn't have this problem as well. Perhaps the more boring/slow software dev requiring OS package managers, because Debian maintainers tend to be a little more level-headed than random Github users? Take your pips, cargos, gems, gradles, composers, and you'll find exactly this vulnerability. The general consensus seems to be "it's impractical to validate all the code we're pulling in, so there's nothing we can do", which is kind of crazy in my opinion. Yes, modern dev does pull in a billion dependencies for every framework, but doing nothing just isn't a problem. We're one NPM hack away from global catastrophe as long as we don't find a solution for problems like these.
- coolspot 5y agoThere is a possibilty that Russia reports that through Interpol Cybercrime or via diplomatic channel, then FBI will have to investigate and possibly lock up Brandon.
- foverzar 5y agoNo, this mechanism is simply not working. Western politicians and public media have been bashing and portraying Russia as "a haven for hackers" for some time now, but it's not like the US is any better from Russian perspective. Russian law enforcement has huge stacks of unsolved cybercrime cases, that are essentially blocked by lack of cooperation from a foreign counterpart.
- mannerheim 5y agoNo reason for the West to cooperate when Russia doesn't either.
- foverzar 5y agoAnd no reason for Russia to cooperate when the West doesn't either. Welcome to global politics, where the leaders of the world's superpowers can't do any better than kindergarten-level "no you!" argument.
- YATA0 5y agoThis is so CURRENTYEAR. We're reaching levels of slacktivism so fucking stupid I honestly don't know where we go from here. I thought changing "master" to "main" was fucking stupid, but this really takes the cake. I foresee a future where someone does this for all Texas IPs because they delusionally believe it's being ran by neo-Nazis, that Texas is a fascist state.
- btown 5y agoBeyond the obvious security considerations, there are also massive legal/IP considerations. peacenotwar is explicitly GPLv3 but was added to node-ipc which still claims to be MIT licensed. Suddenly, any user shipping code dependent on node-ipc or Vue could be in violation of that license. IANAL and don’t know if unknowing breach of the GPL would be enforceable… but zooming out, it’s worth noting that deep software supply chains can carry risk beyond just the risk of an explicit coded attack.
- lobocinza 5y agoOur phones have all kinds of spyware on it from the vendor, from Google and from 3rd party apps. They probably also have, as well as routers, tons of vulnerabilities know but not fixed due to the lack of interest from the vendors. Sometimes Google cancel accounts blocking access to all of it's data without giving reason or recourse. It's 'funny' and hypocritical (as many folks here work for Google and other companies related to aforementioned issues) that we're condemning a dude for getting emotional and causing limited damage on cyberspace while a crazy dude is wrecking destruction on meatspace, killing thousands and threatening the World with nuclear war. I understand the fears that this can undermine this nice thing we have that is opensource. Though the nice thing is that individuals voluntarily share code for whatever intrinsic reasons they have. MIT provides no warranty of any kind and there's no moral obligation to serve and make it corp-friendly. As developers our code is generally the only 'real' power we have and we can't deny that guy his agency. RIAEvangelist was sloppy and probably will suffer consequences for his activism. Being banned from Github and NPM registry are expected and fair due to probable ToS violations and the interest of the organizations in preserving trust. But I fail to see how what he did is more or less ethical than financial sanctions like those recent applied to Russia. If he were to make it look like a mistake it would save him the trouble because ignorance/incompetence are socially accepted.
- ComradePhil 5y agoWhat's next? Prescribe wrong medications to Russians?
- foverzar 5y agoYou know what this is? This is a Civil World War. And it is only just starting.
- dgellow 5y agoPeople focus on the attack itself and reasons behind it. I feel that we are missing the bigger picture here: these type of supply chain attack in the open source world is a systematic problem. It’s a direct result of assumptions baked into services such as npm, pypi, rubygems, etc and assumptions people have regarding 3rd party dependencies. The blast radius is monstrously giant. We seem to be still very naive in the way we approach, use, and implement those type of system, with an assumption that maintainers are working in good-faith and reliable. I don’t know how things should be, and I don’t like to think of contributors and maintainers as a threat, but we have enough examples now to know ignore that risk is a fundamental issue.
- lithos 5y agoI agree here, it's insane the number of dependencies JS developers are willing to take on. A decent sized project will see tens of thousands of extra files added to it (even if a lot of it is noncode stuff like licensing). From an outsider it even looks like employability of someone goes up if they manage to add extra dependencies to a project, since they can point to their download count to a prospective employer. It's insane how much legal liability a company is at for agreeing to so many unread licenses. And how much attack surface they're exposing themselves to with their sprawling dependency chains.