Top issues
Detected presence of software components with political protest dependencies.
Causes risk: protestware dependencies found
threats
Problem
Authors of open source software may decide to use their projects to spread political messages. Running software packages that include protestware dependencies may trigger protest-related functions when executed in the targeted environments or geographies. Protest-motivated code is commonly implemented as a simple display of harmless messages that call for peace. However, over time protestware may evolve to include code that performs excessive logging, issues denial of service, or even deletes user files. Software packages that depend on protestware code are considered to be potentially unwanted applications. When political activism escalates to inclusion of destructive code, additional malware detection policies trigger to flag malicious intent.Prevalence in npm community
0 packages
found in
Top 100
2 packages
found in
Top 1k
35 packages
found in
Top 10k
2.12k packages
in community
Next steps
Inspect behaviors exhibited by the detected software components.
If the software behaviors differ from expected, investigate the build and release environment for software supply chain compromise.
Revise the use of components that raise these alarms. If you can't deprecate those components, make sure they are well-documented.
Avoid using this software package until it is vetted as safe.
Top behaviors
Executes files during installation or upon launch.
execution
Prevalence in npm community
Behavior often found in this community (Common)
95 packages
found in
Top 100
726 packages
found in
Top 1k
7488 packages
found in
Top 10k
4.56M packages
in community
Contains unusually long strings.
anomaly
Prevalence in npm community
Behavior often found in this community (Common)
26 packages
found in
Top 100
134 packages
found in
Top 1k
2067 packages
found in
Top 10k
896.14k packages
in community
Might communicate to server over HTTP using XMLHttpRequest.
network
Prevalence in npm community
Behavior often found in this community (Common)
3 packages
found in
Top 100
27 packages
found in
Top 1k
565 packages
found in
Top 10k
225.51k packages
in community
Makes HTTP POST requests.
network
Prevalence in npm community
Behavior often found in this community (Common)
1 packages
found in
Top 100
13 packages
found in
Top 1k
197 packages
found in
Top 10k
126.14k packages
in community
Makes HTTP GET requests.
network
Prevalence in npm community
Behavior often found in this community (Common)
9 packages
found in
Top 100
56 packages
found in
Top 1k
868 packages
found in
Top 10k
335.76k packages
in community
Top vulnerabilities
No vulnerabilities found.