Toutes les vulnérabilités
HIGHSupply chainexploited in the wild

NPM-COLORS-FAKER-2022

npm · colors, faker

Résumé

In January 2022, maintainer Marak Squires intentionally sabotaged his own widely used libraries colors (over 20 million weekly downloads, ~19,000 dependents) and faker as a protest over uncompensated open-source maintenance. colors v1.4.44-liberty-2 and faker v6.6.6 introduced an infinite loop that printed 'liberty liberty liberty' followed by garbage characters, bricking thousands of downstream applications including AWS CDK tooling. This was sabotage rather than an external compromise, but it broke build pipelines across the ecosystem.

Références

Vulnérabilités liées

Tout Supply chain →