Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of Ukraine
Blog post from Snyk
In March 2022, npm package maintainer RIAEvangelist introduced protest-related code into the widely used node-ipc dependency, creating a software supply chain incident that affected downstream projects including Vue.js CLI and reportedly Unity. Briefly available node-ipc versions 10.1.1 and 10.1.2 contained obfuscated code that checked users’ geolocation and, when Russia or Belarus was detected, recursively overwrote files with a heart symbol; the payload was later removed and those releases were deprecated. Subsequent node-ipc releases, including 9.2.2 and 11.x, added the peacenotwar package, which created a war-related message file on users’ desktops, while version 9.2.2 reached stable dependency chains used by many projects. Snyk tracked the incident under CVE-2022-23812 and related advisories, emphasizing that trusted maintainers and transitive dependencies can introduce significant risks despite being outside an application’s direct codebase. Recommended responses included updating affected tools such as Vue CLI and Unity, avoiding or pinning node-ipc to known-safe versions, using dependency overrides, and monitoring open-source dependency changes through security scanning and supply-chain management practices.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.