Article 5TVN4 Dev corrupts NPM libs 'colors' and 'faker' breaking thousands of apps(Bleeping Computer)

Dev corrupts NPM libs 'colors' and 'faker' breaking thousands of apps(Bleeping Computer)

by
corbet
from LWN.net on (#5TVN4)
Bleeping Computer reportson the latest NPM mess: the developer of the "faker" module deleted thecode and it's development history from GitHub (with a force push), replacedit with a malicious alternative, and broke dependencies for numerousapplications.

The reason behind this mischief on the developer's part appears tobe retaliation-against mega-corporations and commercial consumersof open-source projects who extensively rely on cost-free andcommunity-powered software but do not, according to the developer,give back to the community.

GitHub has evidently called this action a violation of its terms ofservice and disabled the owner's account; NPM has restored a previousversion of the code.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments