Junglewise Threat Intelligence

RIAEvangelist node-ipc unauthorized message delivery on desktop

Severity: info · CVSS 3.3 · Published 2022-03-16

Technologies: RIAEvangelist Node-Ipc. Vendors: npm.

Executive brief

The node-ipc library, a tool used for communication between different software processes, was updated by its maintainer to include code that writes a political message to the user's desktop. While this specific version does not delete data, it represents a "protestware" behavior where a developer intentionally alters software to display unsolicited messages. Organizations using this library should ensure they are not using the affected versions to avoid unexpected system behavior and potential reputational risks.

Technical details

The maintainer of node-ipc introduced a behavior change in version 11.0.0 (often categorized as protestware) that programmatically creates a file on the user's desktop containing a message regarding the Russia-Ukraine conflict. This action is triggered automatically upon the library's execution. While this specific version range (11.x) is distinct from the more destructive 'peacemail' versions that targeted specific IP ranges to overwrite files, it still constitutes unauthorized file system modification. The issue was addressed in version 12.0.0 by reverting the library to a clean state based on version 10.1.0. Users are advised to upgrade to version 12.0.0 or downgrade to 10.1.0.

Affected products

  • RIAEvangelist node-ipc >= 11.0.0, < 12.0.0

Timeline

  • 2022-03-16: disclosed: Advisory published for behavior change in version 11.0.0.
  • 2022-03-16: patched: Version 12.0.0 released to revert changes.

References

Related threats