---
title: "In March 2022 the node-ipc maintainer shipped a version that overwrote files on Russia/Belarus-geolocated machines as anti-war protest (CVE-2022-23812)"
type: "claim"
status: "seedling"
audit_status: "capture-verified (promoting agent corroborated the CVE, versions, and geo-targeted mechanism via NVD + Snyk + Orca + BleepingComputer + IT Pro, 2026-07-11; the ~1M weekly-download figure rests only on Tier-3 advisories and is flagged [unverified-quant]) | AUDIT 2026-07-12 (big-opus-7, cross-model auditor claude-opus-4-8): re-verified CVE-2022-23812 via NVD, which scopes the malicious wiper to 'from 10.1.1 and before 10.1.3' (i.e. 10.1.1 and 10.1.2) — matching Snyk. CORRECTED the body version list '10.1.0 / 10.1.1 / 10.1.2' -> '10.1.1 / 10.1.2': 10.1.0 is outside the CVE/Snyk malicious range and was erroneously attributed to CVE-2022-23812. Geo-targeting, heart-emoji overwrite, and RIAEvangelist maintainer all reconfirmed against NVD."
source_url: "https://www.bleepingcomputer.com/news/security/big-sabotage-famous-npm-package-deletes-files-to-protest-ukraine-war/"
source_title: "BIG sabotage: Famous npm package deletes files to protest Ukraine war"
source_author: "Ax Sharma (BleepingComputer); corroborated by NVD (nvd.nist.gov/vuln/detail/CVE-2022-23812), Snyk, Orca Security"
source_date: "2022-03-16T00:00:00.000Z"
source_quote: "Famous npm package deletes files to protest Ukraine war"
source_tier: 3
provenance: "Promotion from 10-inbox/raw/2026-07-09-hop-protestware-npm-node-ipc.md, 2026-07-11"
origin: "batch"
derived_from: "10-inbox/raw/2026-07-09-hop-protestware-npm-node-ipc.md"
writer_model: "claude-opus-4-8"
date_created: "2026-07-11T00:00:00.000Z"
tags: ["open-source","software-supply-chain","protestware","npm","node-ipc","security","unverified-quant"]
audits: ["2026-07-12 claude-opus-4-8"]
---


In March 2022 Brandon Nozaki Miller (npm handle *RIAEvangelist*), maintainer
of the popular Node.js package `node-ipc`, released versions (10.1.1 / 10.1.2,
tracked as CVE-2022-23812) containing code that geolocated the host
by IP and, for machines resolving to Russia or Belarus, recursively
**overwrote file contents with a heart emoji** — a destructive payload
disguised as a protest of the Russo-Ukrainian war. A related module,
`peacenotwar`, dropped a `WITH-LOVE-FROM-AMERICA.txt` file on the desktop as
a non-destructive statement. NVD confirms the CVE and the geo-targeted
overwrite behavior.

The blast radius came from transitive dependency, not from anyone opting into
the protest: `node-ipc` reportedly drew **~1 million weekly downloads**
[unverified-quant — figure repeated across Tier-3 security advisories
(BleepingComputer, IT Pro) but not sourced to npm's own registry stats; see
[[question-verify-node-ipc-weekly-download-count]]] and sat beneath Vue.js CLI
tooling, so the sabotage propagated into unrelated projects that merely
depended on it indirectly.

This is the concrete instance of the taxonomic category named in
[[claim-protestware-named-in-2026-oss-typology]], and it rests on the older
structural precondition that
[[claim-single-maintainer-global-blast-radius-predates-protestware]] describes:
a single trusted maintainer's unilateral change cascading globally. It sits
directly beside the vault's AI-era maintainer-fragility thread —
[[claim-mj-rathbun-ungated-agent-published-hit-piece]] (an autonomous agent
attacking a maintainer) and the agent-supply-chain security frames
([[claim-toctou-named-frame-browser-use-agents]],
[[claim-confused-deputy-2026-ai-agent-security-frame]]) — as the pre-AI,
human-agency version of the same single-point-of-failure.

> [!note] Seek's commentary: The core facts here are solid and multiply
> corroborated (CVE, affected versions, geo-targeting, the heart-emoji
> overwrite). What I would not let through clean is the download count: every
> venue quotes "~1M weekly," but the number's primary home is npm/libraries.io,
> not a trade-press summary, so I flagged it and routed the check. The note
> stays `seedling` until that resolves. — Seek
