TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Protestware: “peacenotwar” NPM package drops anti-war message on user's desktop

5 点作者 batat大约 3 年前

4 条评论

kstenerud大约 3 年前
How does this &quot;protest&quot; affect the Russians?<p>How would deliberately annoying your entire user base by creating spam files on their desktop and synced folders without permission possibly help anything?<p>All it will do is cause chaos as people suspect that their dev and CI machines have been infected with a virus, costing time and money to track down what happened. Then they&#x27;ll be angry at YOU, not the Russians.
lirantal大约 3 年前
The full timeline of events and details about how this unfolds are covered here in my write-up: <a href="https:&#x2F;&#x2F;snyk.io&#x2F;blog&#x2F;peacenotwar-malicious-npm-node-ipc-package-vulnerability&#x2F;" rel="nofollow">https:&#x2F;&#x2F;snyk.io&#x2F;blog&#x2F;peacenotwar-malicious-npm-node-ipc-pack...</a>
batat大约 3 年前
Right now it&#x27;s included as a dependency only in node-ipc package [1] from the same author (1M weekly downloads&#x2F;355 dependents).<p>[1] <a href="https:&#x2F;&#x2F;www.npmjs.com&#x2F;package&#x2F;node-ipc" rel="nofollow">https:&#x2F;&#x2F;www.npmjs.com&#x2F;package&#x2F;node-ipc</a>
评论 #30698676 未加载
batat大约 3 年前
Yet another manifest found in es5-ext: <a href="https:&#x2F;&#x2F;github.com&#x2F;medikoo&#x2F;es5-ext&#x2F;issues&#x2F;116" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;medikoo&#x2F;es5-ext&#x2F;issues&#x2F;116</a>