Open Source Maintainer Sabotages Code to Wipe Russian, Belarusian Computers

This page summarizes the projects mentioned and recommended in the original post on /r/worldnews

Civic Auth - Auth in Less Than 5 Minutes
Civic Auth comes with multiple SSO options, optional embedded wallets, and user management — all implemented with just a few lines of code. Start building today.
www.civic.com
featured
InfluxDB high-performance time series database
Collect, organize, and act on massive volumes of high-resolution data to power real-time intelligent systems.
influxdata.com
featured
  1. node-ipc

    A nodejs module for local and remote Inter Process Communication (IPC), Neural Networking, and able to facilitate machine learning. (by RIAEvangelist)

    Github Advisory Database entry for the original vulnerability. It links to this file which, if you decode all of the obfuscated crap, relies on an external service at ipgeolocation.io to geolocate the user. If ipgeolocation.io says you're in Russia - even if you aren't - it will attempt to wipe your PC. IP geolocation is unreliable, and always has been.

  2. Civic Auth

    Auth in Less Than 5 Minutes. Civic Auth comes with multiple SSO options, optional embedded wallets, and user management — all implemented with just a few lines of code. Start building today.

    Civic Auth logo
  3. peacenotwar

    Discontinued Attempts to determine if the computer its running on has an IP originating from Russia or Belarus. If it is then depending on the version of the malware either attempts to delete all files on the computer, or creates a text file on the computers desktop protesting the war in ukraine.

    Just an accusation that their D.C. based NGO is downed by an account that joined github yesterday. Said NGO was set up in 2014, monitors human right infringements in Belarus, Russia, and other post Soviet states, and "has been in contact with over 2,500 whistleblowers that provided detailed reports on various kinds of abuse happening there."

  4. Github Advisory Database entry for the original vulnerability. It links to this file which, if you decode all of the obfuscated crap, relies on an external service at ipgeolocation.io to geolocate the user. If ipgeolocation.io says you're in Russia - even if you aren't - it will attempt to wipe your PC. IP geolocation is unreliable, and always has been.

  5. gitian-builder

    Build packages in a secure deterministic fashion inside a VM

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • gotta admit, gadgetbridge is awesome!

    1 project | /r/fossdroid | 2 Jun 2022
  • Any updates on Rust, and node ipc?

    1 project | /r/rust | 23 Mar 2022
  • Anonymous Takes Anti-Putin Battle to Russian People with Printer Attack to Disrupt Kremlin's Propaganda

    1 project | /r/worldnews | 21 Mar 2022
  • Embedded Malicious Code in node-ipc

    4 projects | news.ycombinator.com | 20 Mar 2022
  • Commentary on the Node-IPC incident and open source supply chains

    2 projects | /r/opensource | 20 Mar 2022

Did you know that JavaScript is
the 3rd most popular programming language
based on number of references?