logo

Protestware taps npm to call out wars in Ukraine, Gaza

ID: 195f62ea-e158-5b85-9fbe-2058eec3ed1f

STIX ID: report--195f62ea-e158-5b85-9fbe-2058eec3ed1f

Feed Name: ReversingLabs Blog

Date Published: 2023-11-16

Date Updated: 2026-04-29

Author: [email protected] (Paul Roberts)

...
...

ReversingLabs details the discovery of “protestware” in npm packages, including e2eakarev and the es5-ext dependency used by @snyk/sweater-comb, which leverage postinstall scripts to display geo-targeted political messages (e.g., related to Ukraine and Gaza). Although these examples were not observed to be malicious, the report underscores software supply chain risk from hidden behaviors in widely used dependencies, references prior destructive protestware incidents, urges deeper scrutiny of dependencies (especially postinstall scripts), and notes that IoCs were collected for the reviewed packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.