"@dominictarr Why was @right9ctrl given access to this repo?"
Response: "he emailed me and said he wanted to maintain the module, so I gave it to him. I don't get any thing from maintaining this module, and I don't even use it anymore, and havn't for years. note: I no longer have publish rights to this module on npm."
https://github.com/dominictarr/event-stream/issues/116#issue...
The takeaway seems to be that you should do a background check on anyone asking to become maintainer of your software.
With that said, this thing seems to have blown up because many large companies (Microsoft included) appear to use or depend upon this package. If none of these companies can lend 15 minutes of their engineers' time to help maintain the free software that they leverage, I can certainly understand the author's desire to let the module's maintenance become someone else's problem.
I think many maintainers would have done the same.
I for sure miss old times when I got .Net framework, maybe some library from 1 or 2 3rd party vendors and I had all I needed for development.
Of course in this case this is made worse by the fact that Javascript is so under-featured by default that you have to pull a ridiculous amount of dependencies to do anything which makes it a lot harder to audit everything. Besides since the language is so dynamic it's easy to write a very small, very powerful "shellcode" that can hook itself up anywhere in the software stack.
If the other dev who injected the backdoor had waited a year or so, pretending to actually maintain the package first, what then?
If you're writing code dealing with sensitive information (say, credit card, cryptocurrency credentials, private information etc...) and you don't even bother to vet your dependencies and when it blows in your face your first reflex is to shift blame on some guy who's giving your source code free on the internet you should really think hard about what you're doing.
Can you imagine that flying in any other industry? "Bridge collapses because company bought crappy steel from some guy off e-bay, but hey he had a trustworthy nickname."
I mean, the injection was finally discovered because of a deprecation warning: https://github.com/remy/nodemon/issues/1442
I wonder how many backdoored node packages there are out there, but judging by how this issue was handled I'd guess probably more than 0.
If there's one positive consequence to this cryptocurrency craze it's that it shines light on our terrible so-called "engineering" practices in the software industry.