An open-source developer, expressing regret for supporting “Fortune 500s”, breaks ~19K projects by corrupting popular NPM libraries; GitHub reverts the changes
Users of popular open-source libraries ‘colors’ and ‘faker’ were left stunned after they saw their applications …
GitHub's rollback matters because widely reused packages can transmit one developer's decision across thousands of downstream projects at once, making package stewardship an operational dependency for their users.
First-order effects
Projects that depend on Colors or Faker face immediate application failures from the corrupted releases; GitHub's reversion is the direct route to restoring those dependencies.
GitHub must treat the package changes as an ecosystem-wide incident, not merely a dispute between a maintainer and individual users of the libraries.
Second-order effects
The incident exposes a gap between npm protections against unauthorized publishing and safeguards for destructive changes made through a maintainer's legitimate access.
Teams using popular npm dependencies have a stronger incentive to control version adoption and assess maintainership risk, rather than treating widely used packages as interchangeable utilities.
Third-order effects
Alongside the later node-ipc sabotage allegation, the episode points to maintainer actions as a recurring supply-chain risk distinct from external account compromise.
If this pattern persists, dependency governance will increasingly center on continuity and change-control practices around critical packages, not just vulnerability scanning and account security.
The trend: Open-source supply-chain governance is expanding from preventing external compromise to managing the concentrated operational power of individual maintainers.
Scoop: Developer sabotages ‘colors.js’ and ‘faker.js’ open-source projects, breaking thousands of projects, in retaliation against big businesses exploiting open-source - @Ax_Sharma https://www.bleepingcomputer.com/ ...
NPM has reverted to a previous version of the faker.js package and Github has suspended my access to all public and private projects. I have 100s of projects. #AaronSwartz https://twitter.com/...
So, oddly one thing I didn't cover in my last article... but it was in the back of my mind when you look into developer psyche and abuse from large orgs who abuse the “free, community aspect” of many FOSS projects. That and rifts in project leadership & poison pills. https://twit…
This is fucking irresponsible. If you have problems with business using your free code for free, don't publish free code. By sabotaging your own widely used stuff, you hurt not only big business but anyone using it. This trains people not to update, 'coz stuff might break. https:…
Removing your own code from @github is a violation of their Terms of Service? WTF? This is a kidnapping. We need to start decentralizing the hosting of free software source code. https://twitter.com/...
Not a fan of the approach. It's never the companies that get hurt over this stuff, just the worker bees who suffer and get fired. https://twitter.com/...
It's notable how the same VC firm consistently finds platforms that centralize previously decentralized efforts then make billions adding usability to accessing other people's Open Source & creative projects. https://a16z.com/...
an #opensource developer (@marak) botched 2 of his javascript packages in order to send a message opensource work should be funded and not just exploited by the big corps that leech off the hard work of passionate devs https://github.com/... He is now being called a terrorist htt…
I'm a huge believer in open source, but these supply chain vulnerabilities are only going to get worse Best practice is to build a Software Bill of Materials (SBOM) & version manage the whole thing, just as you would with enterprise IT https://www.theverge.com/...
Dev introduces an infinite loop that bricked thousands of projects that depend on their colors.js & faker.js packages. It's in protest of corporations benefiting from Open Source. GitHub responds by reverting the change & banning their account. Centralization strikes again. https…
While what the dev did was a bit rash and arguably at least somewhat unethical, GitHub suspending his account due to him modifying his own intellectual property is relatively more unethical. The license for his software implies no warranty etc. https://twitter.com/...
Surprised the “chaotic” outcome like this isn't seen more often with so much of programming depending on random devs maintaining projects for free. Ethically pretty interesting too since it is their package/project to with what they want (for the most part). https://twitter.com/.…
https://www.bleepingcomputer.com/ ... Are “packages” that are in external repository and automatically update one of the worst ideas when it comes to code safety / security? “Yeah I'll pull and execute arbitrary code from some open source repo” - it always had “wtf” vibes to me.
regardless of any other feelings about the validity of the dev doing this (I personally err on the side of it was dumb) I feel like the real story is how GitHub rolled it back and suspended his account for updating his own project ‘wrong’ https://twitter.com/...
I wish this developer found a different outlet for his frustrations. I get it, some orgs use open source and don't give back. But by this sabotage, you're only teaching people not to trust #OpenSource Dev corrupts NPM libs, breaking thousands of apps https://www.bleepingcomputer.…
How can we even start talking about supply chain security and sustainability if a maintainer publishing a bad npm package version breaks everyone instantly? Stable, deterministic pinning is table stakes. https://www.theverge.com/...
if your app pulls random code from the internet to run you deserve everything you get linking to other people's repositories does not count as source control https://twitter.com/...
This is the kind of thing that desperate people do when they aren't paid for their work. I know open-core is a dirty word, but we need a better model for #FOSS than we have. Otherwise, well this is the beginning. CC @ChrisLAS @CoderRadioShow https://www.bleepingcomputer.com/ ...
srsly what is this TL? OSS dev @marak sabotages his own js libs w over 20M DL/week & 20K dependents, crashing 1000s of apps. Github reverts libs & suspends his account, for sabotaging his own code. he also suggests Aaron Swartz was murdered for discovering MIT pedo ring 🤯 https:/…
Good luck to Marak Squires for ever getting hired anywhere in the future. Impact appears significant, including AWS' CDK. https://www.bleepingcomputer.com/ ...