Protestware & Sabotage 2022 Incident #17

es5-ext / styled-components

Estimated Financial Impact
Minimal
Blast Radius
Non-destructive protest messages to Russian users

What Happened

Multiple npm packages including es5-ext and styled-components added post-install messages directed at Russian/Belarusian users protesting the Ukraine invasion. The behavior was non-destructive but constituted unexpected behavior in dependencies.

○

Risk Guard: Partial

PACKAGE_INSTALL_SCRIPTS detects anomalous postinstall messages

Risk Guard Check Codes That Flag This Incident

PACKAGE_INSTALL_SCRIPTS

How Every Tool Performed

0 Caught 2 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Partial PACKAGE_INSTALL_SCRIPTS detects anomalous postinstall messages
Socket Partial May detect install script anomaly
Snyk Missed No capability for this attack class
Sonatype (Nexus) Missed No capability for this attack class
Black Duck Missed No capability for this attack class
Endor Labs Missed No capability for this attack class
← atomicwrites deletion left-pad removal →