Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Protestware in JavaScript UI Toolkits on npm Target Russian ...

Blog post from Socket

Post Details
Company
Date Published
Author
Olivia Brown
Word Count
1,009
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team identified hidden protestware within npm packages, specifically targeting Russian-language users accessing Russian or Belarusian domains. The packages, @link-loom/ui-sdk and @link-loom/react-sdk, have embedded code that disrupts user interaction on these sites and plays the Ukrainian national anthem for users revisiting the sites after three days. This functionality, present in specific versions of these packages, is hidden in the JavaScript UI toolkits used for React-based web applications. These actions are triggered by specific browser language and domain conditions, rendering the sites unresponsive and looping audio playback. Although the protestware functionality is absent in the latest versions, the earlier versions continue to affect users under certain conditions, prompting the package creator to deprecate the affected versions and develop a new framework without the controversial features.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.