Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of Ukraine

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal
Word Count
4,169
Company Posts That Month
28
Language
English
Hacker News Points
312
Post removed?
No
Summary

In March 2022, npm package maintainer RIAEvangelist introduced protest-related code into the widely used node-ipc dependency, creating a software supply chain incident that affected downstream projects including Vue.js CLI and reportedly Unity. Briefly available node-ipc versions 10.1.1 and 10.1.2 contained obfuscated code that checked users’ geolocation and, when Russia or Belarus was detected, recursively overwrote files with a heart symbol; the payload was later removed and those releases were deprecated. Subsequent node-ipc releases, including 9.2.2 and 11.x, added the peacenotwar package, which created a war-related message file on users’ desktops, while version 9.2.2 reached stable dependency chains used by many projects. Snyk tracked the incident under CVE-2022-23812 and related advisories, emphasizing that trusted maintainers and transitive dependencies can introduce significant risks despite being outside an application’s direct codebase. Recommended responses included updating affected tools such as Vue CLI and Unity, avoiding or pinning node-ipc to known-safe versions, using dependency overrides, and monitoring open-source dependency changes through security scanning and supply-chain management practices.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.