Top issues
Detected presence of software components with political protest dependencies.
Causes risk: protestware dependencies found
threats
Problem
Authors of open source software may decide to use their projects to spread political messages. Running software packages that include protestware dependencies may trigger protest-related functions when executed in the targeted environments or geographies. Protest-motivated code is commonly implemented as a simple display of harmless messages that call for peace. However, over time protestware may evolve to include code that performs excessive logging, issues denial of service, or even deletes user files. Software packages that depend on protestware code are considered to be potentially unwanted applications. When political activism escalates to inclusion of destructive code, additional malware detection policies trigger to flag malicious intent.Prevalence in npm community
0 packages
found in
Top 100
2 packages
found in
Top 1k
35 packages
found in
Top 10k
2.12k packages
in community
Next steps
Inspect behaviors exhibited by the detected software components.
If the software behaviors differ from expected, investigate the build and release environment for software supply chain compromise.
Revise the use of components that raise these alarms. If you can't deprecate those components, make sure they are well-documented.
Avoid using this software package until it is vetted as safe.
Top behaviors
Executes files during installation or upon launch.
execution
Prevalence in npm community
Behavior often found in this community (Common)
95 packages
found in
Top 100
726 packages
found in
Top 1k
7488 packages
found in
Top 10k
4.56M packages
in community
Contains unusually long strings.
anomaly
Prevalence in npm community
Behavior often found in this community (Common)
26 packages
found in
Top 100
134 packages
found in
Top 1k
2067 packages
found in
Top 10k
896.14k packages
in community
Converts binary data to its string representation, commonly used in obfuscation.
packer
Prevalence in npm community
Behavior often found in this community (Common)
40 packages
found in
Top 100
305 packages
found in
Top 1k
3796 packages
found in
Top 10k
1.13M packages
in community
Serializes data into the JSON format.
file
Prevalence in npm community
Behavior often found in this community (Common)
34 packages
found in
Top 100
218 packages
found in
Top 1k
3028 packages
found in
Top 10k
1.25M packages
in community
Concatenates strings.
behavior
Prevalence in npm community
Behavior often found in this community (Common)
72 packages
found in
Top 100
465 packages
found in
Top 1k
5356 packages
found in
Top 10k
1.75M packages
in community
Top vulnerabilities
No vulnerabilities found.