The npm package node-ipc was turned into a supply-chain security incident after its maintainer added the peacenotwar dependency to releases 11.0.0 and 9.2.2, leading to the assignment of CVE-2022-23812. Reports said the affected code queried ipgeolocation.io to determine whether a system was located in Russia or Belarus and, on matching hosts, traversed directories and overwrote files with a heart emoji. The issue drew broad scrutiny because node-ipc was widely used in downstream JavaScript and Node.js projects, raising concerns that a politically motivated change in a popular open source package could propagate destructive behavior through software supply chains.
The maintainer described peacenotwar as "protestware" intended as a response to Russia's invasion of Ukraine and publicly framed it as non-destructive, while outside reporting and security writeups characterized the incident as sabotage and warned of file-wiping behavior. Published mitigations advised organizations to avoid the affected node-ipc versions, pin to 9.2.1 or 10.1.0, and use dependency controls such as package overrides or Yarn resolutions to block the malicious releases from being pulled into builds.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
In comments to Motherboard, RIAEvangelist denied that the code wiped computers and said it only placed a file on the desktop, while backlash mounted on the node-ipc GitHub page.
A public analysis documented the malicious behavior in node-ipc, tied it to CVE-2022-23812, and recommended mitigations including pinning to node-ipc 9.2.1 or 10.1.0 and using npm overrides or Yarn resolutions.
RIAEvangelist released the npm package peacenotwar and explicitly described it as "protestware" intended to add a peace message to users' desktops as a protest against Russia's aggression.
When the geolocation check matched Russia or Belarus, the malicious node-ipc code recursively traversed directories and overwrote files with a heart emoji, constituting the destructive behavior associated with CVE-2022-23812.
node-ipc versions 11.0.0 and 9.2.2 incorporated peacenotwar, and the affected commit range introduced code in dao/ssl-geospec.js that queried ipgeolocation.io and targeted systems in Russia or Belarus.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
vice.com
Open sourcenpmjs.com
Open sourcegist.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.