A developer of the popular open-source networking tool node-ipc allegedly sabotaged its code to wipe data on computers that use the tool in Russia and Belarus
The shortsighted protest has caused a massive uproar in the open source community. — A technologist and maintainer …
Later coverage grouped deliberate library sabotage under the rise of protestware, making node-ipc a concrete example of maintainership becoming a channel for political intervention rather than solely software stewardship.
First-order effects
Computers using the affected node-ipc code in Russia and Belarus face the alleged data-wiping behavior, while node-ipc users elsewhere must determine whether their deployed versions include it.
The allegation puts the node-ipc maintainer and the project’s trustworthiness at the center of the open-source community’s immediate backlash.
Second-order effects
Organizations that inherit node-ipc through dependency trees face a new review and remediation burden, much as the earlier corrupted NPM libraries showed how one developer action can disrupt many downstream projects.
The episode gives package consumers a reason to treat maintainer-driven changes as an operational risk alongside ordinary bugs and security defects.
Third-order effects
If protestware incidents persist, open-source ecosystems will face pressure to separate a maintainer’s ability to publish code from the ability to impose destructive behavior on downstream users.
The underlying shift is from viewing dependency risk as mainly technical to recognizing governance and maintainer incentives as supply-chain risks.
The trend: Open-source dependency ecosystems are increasingly confronting protestware as a governance risk created by the concentrated power of individual maintainers.
The malicious code was added in the node-ipc npm library, v10.1.1 -This module has roughly 1 million weekly downloads -The malicious code will “wipe the file contents and replace it with a heart emoji” -The malicious code executes for users in Russia and Belarus https://twitter.c…
OSS is fundamentally built on trust. For 30+ years, that model has worked well. But when maintainers deliberately break their communities trust, it really does put the whole system at risk. Because it does become much easier to argue for silos and not to share.
Although this may have started out as a peaceful “non-destructive” protest by the developer with ‘peacenotwar’ module, the addition of blatantly destructive payload to ‘node-ipc’ raised serious concerns in the community ⚠️ given the dev also maintains ~40 popular npm packages. ht…
I talked about this yesterday wrt pinning your dependencies, but these sorts of actions, even if the rationale comes from a good place, are NOT OK. https://twitter.com/...
What a stupid way to do protesting and undermines the entire TRUST that has been vested in the developer. Introducing malware into mainline dependencies as an act of protest? God damn, you guys should stop programming! 😡 https://twitter.com/...
I'm all for creative ways of pushing back against Russian aggression. But this...this ain't it. The open source ecosystem is too valuable and important to corrupt for political purposes like this. Wrong way, go back, do not pass go, do not collect $200. https://twitter.com/...
New: the maintainer of a piece of open software downloaded over one million times a week has sabotaged the code to wipe computers that use it in Russia and Belarus. Massive response from open source community pushing back against his actions https://www.vice.com/... https://twitt…
“maintainer of a popular piece of open source software has deliberately sabotaged their own code to wipe data on computers that used the program in Russia and Belarus, and has faced a massive backlash for doing so, according to messages posted on...Github” https://www.vice.com/..…
In the software description, the maintainer wrote that “This module will add a message of peace on your users' desktops.” But it actually wiped machines https://www.vice.com/...
Researchers are tracking a number of open-source code packages on GitHub that are being turned into “protestware,” code that displays anti-war messages or casualty stats to users w/ RU or Belarusian IPs. Other protestware wipes files for RU/BY users. https://krebsonsecurity.com/ …