Software is becoming more interdependent, and that’s a big security problem

by Reima Budd on Jun 28, 2022 Software 15 Views


n 16 March, 20 days after Russia invaded Ukraine, users of the Vue.js development framework were panicking. Vue is a set of tools that makes it easier for developers to build interfaces for websites and web applications, including at companies like Facebook, Netflix and Nintendo. According to BuiltWith, it powers 19.8 per cent of the world’s biggest 10,000 websites.

So, what does a popular programming tool have in common with the war in Ukraine? Under the hood, Vue, like all tools of its kind, relies on a bundle of other software packages that it automatically downloads. Software packages make it easier for programmers to add functionality to their applications without having to code it from scratch.

In this case, Vue included a dependency on a package called “node-ipc”, whose developer decided to add a small amount of code that would create a text file containing anti-war messages on the desktops of those who use it. But if the package was installed on a device with a Russian or Belarussian IP address, it would also start wiping files from the device and replacing them with a heart emoji.

This was not the first incident of its kind. Earlier this year, the developer of two other popular packages sabotaged them by modifying them to produce gibberish text instead of their expected output.

These incidents show how software developers rely on an increasingly large ecosystem of third-party packages. While these packages can greatly simplify and speed up development, they also have wide security implications.

Read more about the blog in-depth here.


Article source:


No comments have been left here yet. Be the first who will do it.

captchaPlease input letters you see on the image.
Click on image to redraw.



Overall Rating:

Latest Comments

For formal settings, this crockery set is perfect. It is robust and impermeable. Most of the time, the material is incredibly thin and delicate. It also resembles glass in appearance. It...
Great game! Lots of fun to play and keep playing! I just wish you'll always have fun  Retro Bowl playing it.
on Sep 30, 2022 about 3D Architectural Rendering Services
  Rather than pondering over the question of how to make it, it would be a wise decision to go for the Social science assignment help assistance, so that you can receive the answers from...
LocalmedStores is one of the top leading online pharmacies in the US that enables you to purchase generic medicines online and get them delivered to your door at economical prices. Our one-stop...
Your SEO experience has helped me a lot. I would recommend wordle and io games to you, please give me the best SEO advice
on Sep 28, 2022 about Familiarize The Process Of SEO

Recent Reviews

Translate To: