I encourage you to find out the definition of Trojan[1] and then find out what Marak did to sabotage his code.
To qualify as a Trojan, Faker.js needed to be:
- advertised as being for a certain purpose
- coded to do something to damage the person who installs it (even if it still does the thing it advertises that it does)
In this case, Marak allowed people who thought they were installed Faker.js and tricked them into installing something that ran an infinite loop, which would break a lot of CI/CD servers and build processes.
In some circumstances, this could easily lead to economic harm. In the worst circumstances, it could take down a vital service (like a health app) and cause people to be seriously harmed.
1. https://en.wikipedia.org/wiki/Trojan_horse_(computing)
2. https://www.theverge.com/2022/1/9/22874949/developer-corrupt...
They were installing a legitimate new version of Faker.js though - which just happened to be running an infinite loop. It's users who trusted Faker.js author to not pull this kind of stuff off and it turned out they were wrong to do that.
http://www.catb.org/jargon/html/T/Trojan-horse.html
If it isn't security-breaking, it isn't a Trojan. I have not seen any evidence that this prank, immature as it may be, resulted in an actual security breach.
Then it isn't a Trojan. By definition.
"A malicious security-breaking program that is disguised as something benign"