meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, March 18th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 March 2022

⏱️ 15 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. npm sabotage; Deepfakes; ATM Rootkit; Mikrotik Scanner; @sans_edu ICS NAC

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, March 18th, 2020 edition of the Sandsenert Storm Center's Stormcast. My name is Johannes Ulrich,

0:10.6

and I'm recording from Jacksonville, Florida.

0:14.5

The war in Ukraine is still dominating the news and also having its effect on network security topics.

0:23.2

For example, the developer of the Node IPC package decided to add a new dependency to the module called Peace Not War,

0:34.9

which apparently is overriding files of users that are located in Belarus or

0:42.0

Russia. It started all harmless enough with a warning message, but then later the code was

0:49.9

modified again and now overrides files four systems located in Belarus and Russia with a simple heart symbol.

1:00.5

Geolocation is done by IP address and of course with some of the ambiguities in geolocation.

1:08.2

This could potentially also affect users outside of the targeted area.

1:15.3

What makes that also so significant is that the Node IPC package is used by the Vue CLA package.

1:23.4

And Vue, of course, Vue.js' major framework, very popular by many developers.

1:30.4

So this is how this particular alteration was included in a number of projects.

1:37.0

And the Peace Not War module apparently was downloaded about 30,000 times at the time when SNCC wrote up a great blog post

1:47.6

with all the details and all the different modifications that these modules went through.

1:52.8

The note IPC package has now been marked as malicious, so hopefully that'll prevent any further

2:00.0

fallout here.

2:01.4

But since it is an important dependency,

2:03.9

marketing as malicious may also cause other things to break.

2:08.8

I wouldn't be surprised to see more packages published like that,

2:13.7

in particular since this peace, not war package is out there now.

2:17.0

There is sort of a template

2:17.9

to follow in order to basically do the same thing that Note IPC did here.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.