JavaScript dev deliberately screws up own popular npm packages to make a point of some sort
- Reference: 1641850705
- News link: https://www.theregister.co.uk/2022/01/10/npm_fakerjs_colorsjs/
- Source link:
The npm packages, faker.js and colors.js, were not hijacked by outsiders, as [1]has been known to happen; rather their creator added code to the software libraries that made them malfunction.
Three days ago, developer Marak Squires [2]added a "new American flag module" to colors.js, a module to simplify printing colored text in the developer console. The new code printed the word "LIBERTY" multiple times and an ASCII-flag to the developer console and went into an endless loop.
[3]
Six days ago, faker.js, used for generating fake data for API testing, also received an unexpected update: it removed the code, added the commit message "endgame," and replaced the ReadMe file with the question, "What really happened with Aaron Swartz?"
[4]
[5]
Swartz, something of an internet legend for his advocacy and tragedy, [6]killed himself almost a decade ago following his indictment for downloaded millions of JSTOR documents from MIT's network. Tomorrow, January 11, 2022, will be the ninth anniversary of his death. Squires appears to prefer [7]a conspiracy theory cited in a recent Twitter post.
The Register emailed Squires for comment. He replied, "brb soup," which at least is more than we typically get from Apple PR.
[8]The inside story of ransomware repeatedly masquerading as a popular JS library for Roblox gamers
[9]GitHub fixes authorisation vulnerability in the NPM JavaScript package registry
[10]NPM packages disguised as Roblox API code caught carrying ransomware
[11]If you're using this hijacked NPM library anywhere in your software stack, read this
Squires perhaps better articulated his concerns through [12]a blog post from April 25, 2021 – preserved via the Internet Archive's Wayback Machine – in which he described a purported attempt to monetize faker.js.
"No one pays for Faker development," Squires wrote. "Recently, we've begun to get sponsorships through services like Open Collective and Github Sponsors. Most of these donations are from fellow developers, and not enterprises or corporations. These donations have helped keep Faker development from stalling completely, but they are not sustainable.
[13]
"I do enjoy working on Faker, but I also can't afford to work for free. Like most of us, I have people who depend on me and I have bills to pay. Not wanting to give up, I decided the best course of action was to try and monetize the Faker project to ensure future sustainable development."
Trying to pay the rent
The plan, he claims, was to create a cloud service based on faker.js. However, he describes finding that another company was using his open source software to create an identical product. The Register has reached out to the company he named to ask about this but we've not heard back.
In November, 2020, Squires said in a now-removed [14]GitHub Issues post that he was "no longer going to support Fortune 500s (and other smaller sized companies) with my free work."
The incident recalls the [15]"left-pad" debacle in 2016 when developer Azer Koçulu unpublished over 250 of his modules from npm.
Developers incorporate npm modules into their applications so they can add functionality without the need to personally implement the borrowed code. By doing so, they add dependencies – modules or libraries their apps depend upon to function – and so when those dependencies break, get subverted, or disappear, that causes problems in for many applications and people.
[16]
[17]Faker.js is incorporated into more than 2,500 other npm packages and is downloaded 2.4 million times per week; [18]colors.js is incorporated into almost 19,000 other npm packages and gets 23 million downloads a week.
Log4j doesn't just blow a hole in your servers, it's reopening that can of worms: Is Big Biz exploiting open source? [19]READ MORE
Suffice to say that the developer community took notice of this disruption and once again wondered aloud what can be done to make the process of creating and maintaining open source projects more sustainable.
GitHub [20]suspended Squires's account and in the meanwhile, his repos remain publicly accessible. The Register has asked GitHub to explain its rationale for doing so but we've not heard back. Npm also reverted the changes Squires made to at least one of his libraries.
In [21]a blog post , Armin Ronacher, director of engineering at software monitoring firm Sentry and creator of Flask, the popular Python web app framework, took the incident as another sign that the open source community needs support. Efforts to help by funding certain projects, he said, don't always work because many foundation libraries get ignored because they're not as visible as other projects.
"Clearly we need to solve funding of Open Source projects and I love that GitHub sponsors is a thing," he wrote. "But I think we need to find a better way to assess [the] impact of libraries than just how many people depend on this on npm or other package managers. Because that's by far not the whole picture." ®
Get our [22]Tech Resources
[1] https://www.theregister.com/2018/07/12/npm_eslint/
[2] https://github.com/Marak/colors.js/commit/074a0f8ed0c31c35d13d28632bd8a049ff136fb6?diff=unified
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ydy6lYK0i1t5vUKNres9XgAAAFI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ydy6lYK0i1t5vUKNres9XgAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ydy6lYK0i1t5vUKNres9XgAAAFI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2013/01/13/anger_death_aaron_swartz/
[7] https://twitter.com/marak/status/1478540823180582914?s=20
[8] https://www.theregister.com/2021/11/16/nobloxjs_typosquatting_discord/
[9] https://www.theregister.com/2021/11/16/github_npm_flaw/
[10] https://www.theregister.com/2021/10/27/npm_roblox_ransomware/
[11] https://www.theregister.com/2021/10/25/in_brief_security/
[12] https://web.archive.org/web/20210516172305/https://marak.com/blog/2021-04-25-monetizing-open-source-is-problematic
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ydy6lYK0i1t5vUKNres9XgAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://web.archive.org/web/20210704022108/https://github.com/Marak/faker.js/issues/1046
[15] https://www.theregister.com/2016/03/23/npm_left_pad_chaos/
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ydy6lYK0i1t5vUKNres9XgAAAFI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://www.npmjs.com/package/faker
[18] https://www.npmjs.com/package/colors
[19] https://www.theregister.com/2021/12/14/log4j_vulnerability_open_source_funding/
[20] https://twitter.com/marak/status/1479200803948830724?s=20
[21] https://lucumr.pocoo.org/2022/1/10/dependency-risk-and-funding/
[22] https://whitepapers.theregister.com/
Is it really that difficult?
If it's widely used, *pay the creator real money*. As well as a community fund of a non trivial amount, sign up for a support contract if it exists.
If you can't contribute money, contribute effort. If you can do neither you shouldn't rely on the product staying around.
Never, ever, blindly pull the latest version into your product without thorough testing, always have a local staging server of known good versions.
For particularly broken but still useful products (thinking of the huge OpenSSL debacle), consider bringing the product in-house and develop your own fork, as the OpenBSD team did with libressl.
Regardless of what opinions the creator has this has happened before, and not enough has been done about it. We should all think ourselves lucky that what the developer did wasn't malicious.
Software license is the answer
OMG how much open source we use at work (Fortune 100) and nobody has even the time to talk about it, let alone pay for it, or even dedicate some time to contribute. All we do is just glue it all together. If I had a company card I would definitely pay and support the maintainers but it is not how big companies operate. Also, nobody really cares because there is no accountability, I’m not going to push my manager tomorrow to pay some random developer I think needs support, I want to be promoted at the end of the day.
On the other hand why the hell developers use those permissive MIT licenses and then sob when their code is monetised without leaving them any coins? Is there no license which would say it is free but only if your turnover is less than $250mil? Surely you want to retain some copyright power in these situations. Or maybe consider using a copyleft license to make sure future generations will have access to this code?
Quantity of Downloads vs Requires
Slight tangent, but related to a point that BinkyTheMagicPaperclip brings up previously: "Never, ever, blindly pull the latest version into your product without thorough testing"
"colors.js is incorporated into almost 19,000 other npm packages and gets 23 million downloads a week."
This scares/worries the systems engineer in me.
If on a WEEKLY basis 23,000,000 downloads (requires/imports) are being done across ~19,000 dependencies, and if a similar relationship holds for other critical dependencies, that seems to suggest a huge number of projects frequently iterating builds and deployments.
Bearing in mind this is a single package the security vulnerabilities of this practice seems stark across the Node.js ecosystem.
Re: This guy is a QAnon twit
Might be the case, but he makes an important point about the sustainability of packages of any sort and the ecosystem they inhabit, i.e. npm in this case, or things like CPAN for Perl...
Something that grows out of a need into a labour of love (hate) that no-one is willing to pay for is, yeah, a bit of a problem.
In that sense I don't blame this guy for saying "I'm not supporting Fortune 500 companies with my time or efforts for free anymore", but yeah... QAnon? Yikes.