TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Protestware: “peacenotwar” NPM package drops anti-war message on user's desktop

5 pointsby batatabout 3 years ago

4 comments

kstenerudabout 3 years ago
How does this &quot;protest&quot; affect the Russians?<p>How would deliberately annoying your entire user base by creating spam files on their desktop and synced folders without permission possibly help anything?<p>All it will do is cause chaos as people suspect that their dev and CI machines have been infected with a virus, costing time and money to track down what happened. Then they&#x27;ll be angry at YOU, not the Russians.
lirantalabout 3 years ago
The full timeline of events and details about how this unfolds are covered here in my write-up: <a href="https:&#x2F;&#x2F;snyk.io&#x2F;blog&#x2F;peacenotwar-malicious-npm-node-ipc-package-vulnerability&#x2F;" rel="nofollow">https:&#x2F;&#x2F;snyk.io&#x2F;blog&#x2F;peacenotwar-malicious-npm-node-ipc-pack...</a>
batatabout 3 years ago
Right now it&#x27;s included as a dependency only in node-ipc package [1] from the same author (1M weekly downloads&#x2F;355 dependents).<p>[1] <a href="https:&#x2F;&#x2F;www.npmjs.com&#x2F;package&#x2F;node-ipc" rel="nofollow">https:&#x2F;&#x2F;www.npmjs.com&#x2F;package&#x2F;node-ipc</a>
评论 #30698676 未加载
batatabout 3 years ago
Yet another manifest found in es5-ext: <a href="https:&#x2F;&#x2F;github.com&#x2F;medikoo&#x2F;es5-ext&#x2F;issues&#x2F;116" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;medikoo&#x2F;es5-ext&#x2F;issues&#x2F;116</a>