Popular JS Package node-ipc Adds Malicious "Protest-ware" On Purpose
Mental Outlaw
In this video I discuss the malicious "protestware" (reall malware) that RIAEvangelist / Brandon Miller Purposefully added to the popular node-ipc package. This is a javascript package that has almost 5 million monthly downloads and results in create a text file on the users desktop called FROM-AMERICA-WITH-LOVE.txt and also corrupts all files on the computer by overwriting their contents with heart emoji's if the user happens to be in Russia or Belarus (or happens to have a Russian/Belarusian geolocation/ip address from using a VPN). This is one of the most shameful things to happen in the opensource community, check this link below for an unoffical list of packages that are affected by this to make sure you are secure.
https://github.com/zlw9991/node-ipc-dependencies-list
News article that goes more in depth about the situation https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/
₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
Monero 45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
Bitcoin 3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
Ethereum 0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
Litecoin MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF
Dash Xh9PXPEy5RoLJgFDGYCDjrbXdjshMaYerz
Zcash t1aWtU5SBpxuUWBSwDKy4gTkT2T1ZwtFvrr
Chainlink 0x0f7f21D267d2C9dbae17fd8c20012eFEA3678F14
Bitcoin Cash qz2st00dtu9e79zrq5wshsgaxsjw299n7c69th8ryp
Etherum Classic 0xeA641e59913960f578ad39A6B4d02051A5556BfC
USD Coin 0x0B045f743A693b225630862a3464B52fefE79FdB
Subscribe to my YouTube channel http://goo.gl/9U10Wz and be sure to click that notification bell so you know when new videos are released. ... https://www.youtube.com/watch?v=2M-L0yPbtPE
153185364 Bytes