[HN Gopher] NPM package compromised by author: erases files on R...
___________________________________________________________________
NPM package compromised by author: erases files on RU / BY
computers on install
Author : asn007
Score : 83 points
Date : 2022-03-16 20:42 UTC (2 hours ago)
(HTM) web link (snyk.io)
(TXT) w3m dump (snyk.io)
| jakub_g wrote:
| I only read it briefly but the HN submission title talks about
| _erasing_ files on RU /BY computers, while the blog post talks
| about _creating_ files on desktop.
|
| Could someone verify which statement is true?
| lights0123 wrote:
| > On March 8, at 7:25PM GMT+2 and less than four hours after
| node-ipc@10.1.3 had been published to roll back the destructive
| payload, a new major version node-ipc@11.0.0 was released on
| the npmjs registry.
|
| The old version erased files, the new one leaves a file on the
| desktop.
| toomuchtodo wrote:
| asn007 wrote:
| I rarely visit HN and mostly lurk here, not sure what you're
| trying to point out.
|
| I was myself hit by the issue, unfortunately, and I strongly
| believe that weaponising open-source is not how things should
| be done, so I decided to post. An attempt to bring this into
| limelight, if you wish
|
| This incident sets a dangerous precedent in breaking a chain of
| trust that today's software development heavily relies on
| toomuchtodo wrote:
| I wasn't suggesting any nefarious intent, only that this was
| the topic that made you go "Today is the day I post."
|
| Sorry to hear you were impacted by this. Software supply
| chain challenges are copious, unwieldy, and everywhere.
| TMWNN wrote:
| >I wasn't suggesting any nefarious intent,
|
| Oh, please. The only thing missing was to accuse asn007 of
| being a "Russian troll", although I suppose you realized
| that that would not be appropriate in this case.
|
| Just own up to your apology.
| toomuchtodo wrote:
| Sorry that's what you took from it, if you're looking for
| an apology. People are interesting, that's all, and I am
| curious about how they tick. There is a difference
| between "How odd!" and "This person is up to no good."
|
| Whether someone is a "Russian troll" or not really
| doesn't concern me, and I wouldn't call someone out if I
| thought they were (that's a mod's problem and poor form),
| nor was that what I was insinuating.
| chizhik-pyzhik wrote:
| Regardless of your political position, this falls well within the
| definition of malware. It's irresponsible for the maintainer to
| allow this: https://github.com/RIAEvangelist/node-ipc/issues/233
| zozbot234 wrote:
| Plenty of existing ransomwares delete user files on everything-
| _but_ -RU machines. Perhaps the maintainer of this package
| subscribes to the old view that "turnabout is fair play".
| [deleted]
| paxys wrote:
| Yup. Although if you do want to get political, I'd say this
| falls under the definition of cyber warfare. Also the
| maintainer didn't only "allow" it, it seems he is the author of
| the malicious module as well.
| superasn wrote:
| Guess it's time to chroot each project folder if you're using any
| package manager or external libraries. Though on second thought
| it's just a band aid as the damage which can be done after
| deployment is far worse than anything before.
| netsharc wrote:
| Guy has his real name on his github page. Googled him, he has a
| Wikipedia page, created by a Wikipedia user with the same
| username as his Github one. Well, I think that says all I need to
| know about his character.
| kmlx wrote:
| - @vue/cli - @vue/cli-ui - node-
| ipc@^9.2.1 - @vue/cli-shared-utils -
| node-ipc@^9.1.1
|
| due to the nature of the ecosystem i feel like
|
| - pinning the dependencies
|
| - running something like renovate
|
| - merging the resulting MR's with quite a delay from when they
| were opened
|
| as some basic steps in mitigating this sort of silly, but
| potentially expensive, stuff.
| hsbauauvhabzb wrote:
| n-1 is a great concept that works right up until log4shell
| starts happening.
|
| The solution is to audit all code you rely on, the i viability
| of that solution is the fault of the npm micro package
| ecosystem.
| btreecat wrote:
| I don't know how I feel about this.
|
| One hand, this is a seemingly non-violent and subtle way to
| protest. On the other, the potential collateral damage is huge
| and just burns all trust with this developer, and is a net harm
| to the ecosystem as a whole.
|
| FOSS is great, because we were actually able to track the changes
| here. But it also points out how many packages go un-checked and
| just installed into a container running with root permissions.
| choward wrote:
| > I don't know how I feel about this.
|
| > One hand, this is a seemingly non-violent and subtle way to
| protest.
|
| You can't be serious. Being non-violent and subtle is no excuse
| for deliberately making software have real side effects on a
| computer that it's not advertised to do, especially a node
| library. Node modules for some reason tend to be very small and
| have trivial tasks like checking if something is a number.
| Imagine if everything shipped with it's own political malware.
|
| No matter how you want to spin it this is completely
| unacceptable and nobody should ever trust this developer again.
|
| > But it also points out how many packages go un-checked and
| just installed into a container running with root permissions.
|
| The fact that "packages go unchecked" doesn't make this okay
| either.
| yesbut wrote:
| it isn't going to stop Putin but it could negatively impact
| normal people. in no universe will the handful of Russian
| programmers impacted by this rise up and overthrow their
| government. but they will be forced to work extra hours
| cleaning up any damage this caused to their system. This is
| really lame virtue signalling that only harms fellow workers
| because their government is terrible.
| afavour wrote:
| But this is pretty much the exact logic sanctions work by.
| Putin and his cronies might lose some super yachts but the
| main aim is to crash the Russian economy, which will hurt
| everyday Russians far more than any leader. Not that I have
| any better ideas, but you could argue this move is in a
| similar vein.
___________________________________________________________________
(page generated 2022-03-16 23:01 UTC)