Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Tracking Protestware Spread: 28 npm Packages Affected by Pay...

Blog post from Socket

Post Details
Company
Date Published
Author
Olivia Brown
Word Count
787
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

Undocumented protestware has been discovered affecting 28 npm packages, designed to disrupt user interactions for Russian-language users visiting Russian or Belarusian domains by disabling mouse interactions and playing the Ukrainian national anthem. Initially found in the SweetAlert2 package, which has over 700,000 weekly downloads, the protestware's spread appears to be unintentional, propagated through copied code across different packages without proper documentation or acknowledgment. The protestware specifically targets users with Russian language settings who visit certain domains, highlighting the broader implications of software being used as a political statement. While the author of SweetAlert2 disclosed the protestware's presence in its recent versions, many other packages containing the code remain undocumented, raising concerns about transparency, trust, and user experience within the ecosystem. Socket’s Threat Research Team has flagged these packages as malware due to their disruptive behavior, urging developers to ensure package transparency and monitor dependencies to prevent unexpected outcomes.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.