Toutes les vulnérabilités
HIGHSupply chainexploited in the wild

NPM-NODE-IPC-PEACENOTWAR-2022

npm · node-ipc, peacenotwar

Résumé

In March 2022, node-ipc maintainer Brandon Nozaki Miller (RIAEvangelist) introduced protestware against the invasion of Ukraine into his widely used package (over 1 million weekly downloads). Versions 10.1.1 and 10.1.2 contained destructive code that geolocated users via an IP API and overwrote/deleted arbitrary files on systems in Russia and Belarus, replacing contents with a heart emoji. Version 11.0.0 added a dependency on his 'peacenotwar' module that wrote a protest message to users' desktops. The destructive variant was tracked as CVE-2022-23812 with a CVSS score of 9.8.

Références

Vulnérabilités liées

Tout Supply chain →