The definition of malicious, according to Merriam Webster[0], is the following
>having or showing a desire to cause harm to someone : given to, marked by, or arising from malice
Was the intention here to cause someone harm? What the intention here malice? Which conversely has this definition[1]
>desire to cause pain, injury, or distress to another
Was this their primary motivation? What evidence do we have that is in fact an action driven by malice? In fact, I don't see any, especially after doing roughly 20 minutes of research, I have arrived at the following:
Reading the public history surrounding the maintainer of these projects, the issue trackers of the repositories, and the maintainers own blog, you may come from a different conclusion entirely. If I was to speculate - and mind you, I am speculating, as I don't know the maintainer personally nor do I claim to understand them completely - there is a clear sense of mental strain they are feeling from the burdens here. Being burnt out, feeling taken advantage of, can lead to very real and deep feels of depression and/or other mental challenges (this I speak first hand to), for starters. I think the maintainer - again, speculating here, however evidence does seem to suggest this - is acting from a place of disillusionment, and possibly is resentful of their status in the word, relative to those benefiting from their contributions to open source software. Are they right to feel this way? Maybe, maybe not. However, is this malice? That's the question. Is this actually malicious? All evidence points to no, its not an act of malice. Its an act of someone who is disillusioned, strained, and struggling. I think the most reasonable interpretation given all the evidence is that they are trying to raise some kind of awareness - albeit in ways that I don't think is well communicated, due to the issues I previously highlighted - most likely.
I could be wrong, I'm just following the publicly available evidence and, its a lot more murky than this is an malicious act by a malicious maintainer acting in malice.
And again, this brings up the broader issue around open source maintainability, longevity, the role of consumer and maintainer, and how to build better symbiotic relationships around that, yet we aren't talking about what lead to this event, which I would argue is more important than what happened.
My ask is for nuance in this conversation, where there is seemingly little.
Unless he's gone absolutely bonkers, he's doing this to intentionally cause damage. The reason for it does not matter, as the definition you posted helpfully points out.
Was it malice when maintainers started adding those posinstall scripts asking for funding? which lead directly to the creation of `npm fund`, for instance. Was that also malice?
Given all the evidence we have - I think its murky. That's my point, at the end of the day.
Arguably, I could say that making millions of dollars off an open source library and not contributing back is malice - yet that argument is rarely given the same open and shut approval.
Mind you, this is bigger, IMO, than `faker.js`, this raises questions around open source software as a whole, that are relevant in this case and beyond
There's nuance in this conversation that is missing so far.
In any other context, it is argument against open source existing.
No, because that did not impair use of those libraries whereas this change deliberately broke every program written by someone who trusted him and used his code under the social contract he offered.
Open source maintainer funding and burnout are real problems but betrayal won't make things better. Imagine if you lived in a house with a bunch of roommates who weren't doing their share of the housework — you're entirely within your rights to stop volunteering to clean the toilet but it's crossing a line if you instead modify it to flush up.
This is very much a philosophical question and I doubt we will resolve it here on HN. However if you want to deem this act malicious I beg you to ask your self: To whom is the malice directed towards, who was harmed the most? What does this act tell us about the industry?
I, on the other hand, see this sabotage as a clear act of love from a fellow worker.
I would also strongly question any “fellow worker” explanation since I'm sure the pain will almost universally be felt by the “fellow workers” who have to update things, reassure their security team, or increasingly start justifying their use of open source software.
It certainly wasn't directed at the large corporations, they have many systems in place to mitigate this type of attack. It was directed at everyone else, like fellow open source devs, contractors, hobby developers, students, and small to medium businesses.
The goal simply appears to be chaos and attention.
If you want to get paid, or you require contribution, use an appropriate license. It's not hard.
aws-cli should not be an attack vector, and if it is, AWS engineers are at fault.
This has been posted before, but Marak seems to be mentally unwell right now, which helps explain but doesn't condone his behavior.
https://abc7ny.com/suspicious-package-queens-astoria-fire/64...
Edit to Add: According to this page https://www.npmjs.com/package/faker
The previous version was 5.x.y and the endgame version was 6.6.6
So, which tools defaulted to magically bumping the dependency from 5.x.y to the 6.x.y? Seems like jumping a major shouldn't automatically happen.
Edit: your comment makes more sense now that I see it was talking about faker.js.
https://github.com/aws/aws-cdk/issues/18322#issuecomment-100...
This floating behavior allowed for it to be overridden locally:
https://github.com/aws/aws-cdk/issues/18322#issuecomment-100...
> Was the intention here to cause someone harm? What the intention here malice?
Yes. Removing / archiving the project – not malice. This, however is absolutely malicious:
let am = require('../lib/custom/american');
am();
for (let i = 666; i < Infinity; i++;) {
if (i % 333) {
// console.log('testing'.zalgo.rainbow)
}
console.log('testing testing testing testing testing testing testing'.zalgo)
}
> Are they right to feel this way? Maybe, maybe not. However, is this malice?Reasoning about Marak's motivation or intentions does have anything to do with whether his actions were ultimately malicious.
> Its an act of someone who is disillusioned, strained, and struggling.
You might be right, but there were a lot of things he could have done before doing what he did, and when he did act, he did it with the intention of causing people distress, frustration and confusion.
> ...its a lot more murky than this is an malicious act by a malicious maintainer acting in malice.
We're really far down a semantic rabbit hole at this point. Ultimately, adding an infinite loop to a widely used package deliberately and without warning is clearly an attempt to 'cause ... distress to another.' There's no two ways about it. Sure, Marak likely felt under-appreciated, mistreated and taking advantage of by large corporations etc but those possible explanations do not absolve him of blame, or mean his actions were not unequivocally malicious. In the legal system, mitigating factors can lead to a lesser charge or a shorter sentence, but even if they do reduce the severity of the outcome, you're still guilty.
The change has an infinite loop, so it literally breaks any software that uses it.