Maintainer Brandon Nozaki Miller added destructive code to node-ipc (1M+ weekly downloads) that overwrote all files with a heart emoji on systems geolocated in Russia or Belarus (CVE-2022-23812, CVSS 9.8). An American NGO in Belarus reportedly had 30,000+ messages documenting human rights abuses wiped. The package was a transitive dependency of Vue.js CLI and Unity Hub.
PACKAGE_ACTIVE_MALWARE detects destructive file-overwriting payload; SOURCE_SINGLE_CONTRIBUTOR pre-existing
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE detects destructive file-overwriting payload; SOURCE_SINGLE_CONTRIBUTOR pre-existing |
| Socket | Caught | Behavioral analysis detects geolocation-based file destruction |
| Snyk | Missed | No malware/protestware detection |
| Sonatype (Nexus) | Caught | Firewall blocks CVE-2022-23812 CVSS 9.8 |
| Black Duck | Missed | No malware detection |
| Endor Labs | Missed | No malware detection |