Executive brief
faker.js version 6.6.6 was intentionally broken by the developer, who also deleted and recreated the GitHub repository with only a single "endgame" commit. This library is a critical dependency for over 2,500 packages used across thousands of applications. The sabotage could disrupt development workflows, CI/CD pipelines, and deployments for downstream users relying on this library.
Technical details
This incident involves deliberate package tampering rather than a traditional security vulnerability. The original faker.js NPM package was updated to version 6.6.6 in a non-functional state, while the source code repository was wiped of all historical content and replaced with a single commit. The attack vector is supply-chain based: any new installation or update of faker.js 6.6.6 will receive the broken package. Both GitHub and NPM have since locked the original developer account. A community fork has been created at https://github.com/faker-js/faker to restore the original codebase. Users should migrate to the fork or revert to earlier versions immediately.
Affected products
- faker.js faker.js 6.6.6
Timeline
- 2022-01-09: disclosed: GSD-2022-1000008 published; faker.js 6.6.6 marked as broken with wiped repository