2 ms·
Did you read the parent article? But, in at least one case—the peacenotwar module in the node-ipc package—an update sabotages npm developers with code intended
by bmj 5y ago
Did you read the parent article?
But, in at least one case—the peacenotwar module in the node-ipc package—an update sabotages npm developers with code intended to wipe data stored in Russia and Belarus. In a March 16 blog post on the malicious code, Liran Tal at Snyk said, “This security incident involves destructive acts of corrupting files on disk by one maintainer and their attempts to hide and restate that deliberate sabotage in different forms.”
This has nothing to do with pace of development, or even the political views of the developers. It has to do with inserting what is essentially malware into open source packages that affect users based on geo-location.
- extheat 5y agoOK, and how is this something unique to the Node.js package ecosystem? What's stopping someone on PyPI/some other PM from doing the same thing? I personally view these more as malicious copycat acts than anything inherent with the ecosystem. Should NPM start manually reviewing all of the packages that go through them, because the handful of abusers? I'm not so sure. The situation on languages without a widely used package manager/ecosystem like C++ I don't think is any better.