TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

My entire PC got wiped Do not download

126 点作者 ahiknsr大约 3 年前

24 条评论

0x38B大约 3 年前
This is disgusting and thoughtless, because it accomplishes nothing but alienating Russian or Belarusian users. It doesn’t attempt to spread the truth or convince people that yes, Russian forces really are committing war crimes. Killing children.<p>I would love for pro-“special operation” Russians to find out why Ukrainian hospitals in the war zone keep their lights off at night. Hint: so they won’t be targeted. Spreading those truths could have done some good, but this… this is merely malicious.
评论 #30722846 未加载
tored大约 3 年前
Me prophetically 2 days ago<p>&gt; software developers are smart enough to not download crap from the internet, but they will gladly run npm install with full user privileges.<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30684416" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30684416</a>
chii大约 3 年前
regardless of the goals, malware is malware.<p>I think there&#x27;s an overton window here which is getting pushed. People need to stop unilaterally imposing their own form of punishment to a group of people, just to make a political statement.<p>It was bad with the BLM saga, but apparently at the time, it was too politically incorrect to say. It is still bad now that the russian invasion is causing an even wider and larger number of such malware.<p>Make political statements with your government, or do it as a standalone organization. Put ads in the papers, media etc. Don&#x27;t use an unrelated platform, such as software distribution platforms to make a political statement - esp. if it harms the end user in some ways. There&#x27;s a name for such action - it&#x27;s called terrorism. I would hope that the people living in civilized society can see that.
评论 #30719621 未加载
评论 #30718879 未加载
评论 #30719422 未加载
评论 #30718733 未加载
StringyBob大约 3 年前
I have no idea who or what to believe, but there is a quote from someone claiming to be a NGO documenting war crimes that has had their records wiped by this <a href="https:&#x2F;&#x2F;github.com&#x2F;IdealismIncinerator&#x2F;node-ipc&#x2F;blob&#x2F;master&#x2F;README.md" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;IdealismIncinerator&#x2F;node-ipc&#x2F;blob&#x2F;master&#x2F;...</a>
sschueller大约 3 年前
This package should be immediately removed from the npm repository and the developer should be permanently banned from publishing npm packages.<p>If you purposely distribute malware you don&#x27;t get to be part of the package registry as you have proven you can&#x27;t handle the responsibility.
评论 #30727789 未加载
sally1620大约 3 年前
Next time someone asks me why you are writing a function yourself instead of using a library, I will show them this.
评论 #30722332 未加载
voldacar大约 3 年前
From github tos:<p>&gt;We do not allow anyone to use our platform in direct support of unlawful attacks that cause technical harms, such as using GitHub as a means to deliver malicious executables or as attack infrastructure<p>Why are they still hosting this? It would seem to violate the CFAA and therefore be unlawful
mfcl大约 3 年前
The package uses <a href="https:&#x2F;&#x2F;github.com&#x2F;RIAEvangelist&#x2F;peacenotwar" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;RIAEvangelist&#x2F;peacenotwar</a> to deliver the message.<p>But I don&#x27;t understand why&#x2F;how it would wipe the PC. Unless I missed something, the code from the package does not delete anything.<p>&gt; This code serves as a non-destructive example of why controlling your node modules is important. It also serves as a non-violent protest against Russia&#x27;s aggression that threatens the world right now.<p>Nah, the author knew it&#x27;s would be controversial. The first sentence is there as an excuse.
评论 #30718297 未加载
评论 #30718473 未加载
评论 #30719176 未加载
x86_64Ubuntu大约 3 年前
This is brutal. I can only imagine the indignation felt if US computers were wiped because of the 2003 invasion.
评论 #30718315 未加载
评论 #30718290 未加载
4oo4大约 3 年前
What the hell are NPM and GitHub doing, are they letting this malware exist since it&#x27;s for the &quot;right&quot; cause? I understand where this guy&#x27;s heart is at but this is wrong on so many levels. I reported this to both of them this morning, and they are still up, I can&#x27;t be the only one. If they don&#x27;t take it down then that is a serious trust issue there, and represents a new reality where people will willingly host malware if it&#x27;s for the correct political cause.<p>I forked the repo to make the README.md more accurate and satirical (and removed the actual malicious code), but sadly I can&#x27;t make a PR since he&#x27;s locked down the repository to only contributors.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;4oo4&#x2F;cyberwarfareispeace" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;4oo4&#x2F;cyberwarfareispeace</a><p>But seriously GitHub and NPM, get your shit together.<p>EDIT: Finally got a response back from NPM and GitHub that they&#x27;re investigating.
评论 #30730282 未加载
seanw444大约 3 年前
At least with Faker.js, it didn&#x27;t act as malware. Simply a deleted project. That was a more respectable protest. This... well it&#x27;s certainly an attention-grabber. But if he wants people to be sympathetic to his message, good luck with that now.
评论 #30720354 未加载
评论 #30719499 未加载
jmrm大约 3 年前
Have the creator thought that a Russian or a Belorussian person who use this software might are against the government or their country?<p>Blaming citizens who are mostly uninformed and mislead due to information control, and have little real power to change what&#x27;s happening, doesn&#x27;t help at all to the current situation.
opisthenar84大约 3 年前
People frequently forget that the actions of one&#x27;s government do not necessarily represent an individual&#x27;s standpoint. Go after high-level officials and oligarchs, but do not go after common folk - they&#x27;ve already lost enough.
评论 #30719031 未加载
评论 #30718653 未加载
rusnoob大约 3 年前
Microsoft maintains GitHub. This is water on their mill. Use solid, corporate backed dotnet, not random soyware. Next you know FOSS is dead in the water.<p>If one random supporter of the current thing can cause such a mayhem, imagine what can happen to any of the projects in 2-3 years: you run update and find your sever wiped out because capitalism is bad or indigenous people of Tuvalu lost a fishing boat or whatever.<p>On the longer run this is the end of community projects in mission critical applications.<p>You are one brain damaging soy latte away from total distaster.
评论 #30735059 未加载
seanw444大约 3 年前
The Issues for node-ipc have devolved so much, and it&#x27;s completely hilarious and entertaining to read.
anthropodie大约 3 年前
I want to mitigate risks like this. Is there a way to limit access to certain directories only while using certain software?
评论 #30720755 未加载
评论 #30719684 未加载
评论 #30718368 未加载
评论 #30726282 未加载
评论 #30718375 未加载
评论 #30725366 未加载
imtringued大约 3 年前
If war is bad why fight a cyberwar as a civillian?
mkeeter大约 3 年前
The node-ipc supply-chain attack also made its way into Unity, albeit in the milder &quot;leave a file on the desktop&quot; form:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;hybridherbst&#x2F;status&#x2F;1504223953627369480" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;hybridherbst&#x2F;status&#x2F;1504223953627369480</a>
stagas大约 3 年前
You can mitigate against those kinds of attacks using npm&#x27;s `--before` option:<p><pre><code> npm i --before=`date -I -d &#x27;-5 days&#x27;` </code></pre> It will only install packages released before the specified date.
评论 #30725012 未加载
vmception大约 3 年前
Check out the other &quot;Issues&quot; there, its going wild!
crazypython大约 3 年前
this only gives the kremlin the ability o say &quot;The West is out to get you&quot;
orangepurple大约 3 年前
Thanks for all the free pizza, and thanks to all the police that showed up to SWAT me. They were really nice fellas.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;RIAEvangelist&#x2F;node-ipc&#x2F;commit&#x2F;088a1ca4d5fe5d175c43ee41718b72b017f6f6a4" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;RIAEvangelist&#x2F;node-ipc&#x2F;commit&#x2F;088a1ca4d5f...</a>
forgotpwd16大约 3 年前
Checking source of module all it does is make a file in desktop. That the issue opener has a troll face as avatar doesn&#x27;t help in taking their claim serious.
评论 #30718169 未加载
评论 #30718281 未加载
评论 #30718259 未加载
jaxrtech大约 3 年前
My guess is that the npm package itself got hijacked? The latest version on npm is v11.1.0 (updated 3 days ago) while master on GitHub is v10.1.0 (updated 9 months ago).
评论 #30718542 未加载