Protestware & Sabotage 2022 Incident #15 CVE-2022-23812

node-ipc / peacenotwar

Estimated Financial Impact
$5-25M
Blast Radius
1M weekly downloads; CVE-2022-23812 CVSS 9.8; 30K files destroyed

What Happened

Maintainer Brandon Nozaki Miller added destructive code to node-ipc (1M+ weekly downloads) that overwrote all files with a heart emoji on systems geolocated in Russia or Belarus (CVE-2022-23812, CVSS 9.8). An American NGO in Belarus reportedly had 30,000+ messages documenting human rights abuses wiped. The package was a transitive dependency of Vue.js CLI and Unity Hub.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE detects destructive file-overwriting payload; SOURCE_SINGLE_CONTRIBUTOR pre-existing

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWARESOURCE_SINGLE_CONTRIBUTOR

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE detects destructive file-overwriting payload; SOURCE_SINGLE_CONTRIBUTOR pre-existing
Socket Caught Behavioral analysis detects geolocation-based file destruction
Snyk Missed No malware/protestware detection
Sonatype (Nexus) Caught Firewall blocks CVE-2022-23812 CVSS 9.8
Black Duck Missed No malware detection
Endor Labs Missed No malware detection
← colors.js / faker.js sabotage atomicwrites deletion →