TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Node-ipc added dependency on maintainer's peacenotwar module

2 pointsby mrmattyboyabout 3 years ago

2 comments

mrmattyboyabout 3 years ago
The peacenotwar module appears to write a file to the user&#x27;s PC. README includes:<p><pre><code> &quot;This code serves as a non-destructive example of why controlling your node modules is important. It also serves as a non-violent protest against Russia&#x27;s aggression that threatens the world right now. This module will add a message of peace on your users&#x27; desktops, and it will only do it if it does not already exist just to be polite.&quot; </code></pre> Link to peacenotwar: <a href="https:&#x2F;&#x2F;github.com&#x2F;RIAEvangelist&#x2F;peacenotwar" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;RIAEvangelist&#x2F;peacenotwar</a><p>An of course the issues come in: <a href="https:&#x2F;&#x2F;github.com&#x2F;RIAEvangelist&#x2F;node-ipc&#x2F;issues" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;RIAEvangelist&#x2F;node-ipc&#x2F;issues</a>
评论 #30702627 未加载
lirantalabout 3 years ago
More detailed write-up on what exactly happened with node-ipc and the events that lead to it from a week ago (March 8th) here: <a href="https:&#x2F;&#x2F;snyk.io&#x2F;blog&#x2F;peacenotwar-malicious-npm-node-ipc-package-vulnerability&#x2F;" rel="nofollow">https:&#x2F;&#x2F;snyk.io&#x2F;blog&#x2F;peacenotwar-malicious-npm-node-ipc-pack...</a>