TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

New Protestware Found Lurking in Highly Popular NPM Package

14 pointsby aviramhaalmost 3 years ago

4 comments

filoelevenalmost 3 years ago
Two packages: styled-components and es5-ext. Both print out console messages on .ru systems, neither one messes with the system’s files.
aviramhaalmost 3 years ago
Just found about it while releasing a package to VS Code marketplace - It appears we can't use the last versions of this package (es5-ext) anymore due to anti viruses marking it as a Hoax malware. I wonder what's people take here - should VirusTotal and anti viruses detect it as malware?
评论 #32045306 未加载
dixie_landalmost 3 years ago
Let’s call it what it is - malware
stevenalowealmost 3 years ago
Is this behavior listed as a feature of the package? If not, it’s malware.
评论 #32045833 未加载
评论 #32046198 未加载