Publishing malware is, and should remain, protected expression.
That said, such a law is difficult to enforce, in a justice system as moribund as ours, so instead we rely on (probably wrong) heuristics about what specific behavior makes us safe, and indeed, whether or not our resources have already been breached. Such behavior is what drives the overwhelming dominance of GMail, which is itself a remarkable tool with which to learn about any person group corporation government on the planet. So in terms of utility its hard to argue that malware is a good to society. Write a malware that installs a patch to prevent a 0-day in known use by a state actor, then I will be a malware fanboy. Not until then.
But in all seriousness, that was one of the most jarring things I found when switching from a Java/Maven stack to JS/NPM. Both Maven and NPM offer similar features for managing dependencies, but anecdotally I found the folks managing Java projects to be a lot more obsessive about carefully managing their dependencies while in the NPM world, it seems almost to be a "best practice" to just use open ranges for your dependencies and automatically update them...
This isn't enforceable in quite a few jurisdictions anyways. The best you can do is "No warranty to the extend permitted by law" at which point this specific use case is pretty much no longer relevant.
If it is advertised as malware, yes. But if it is advertised as a working open source project - but in reality is malware, then this just destroys trust into open source in general.
I guess it is good, that these things come up, to think about why we trust the dependencies and repositories and their maintainers.
Because it seems, no we cannot just trust them. And now I am more conscious about it.
OSS should be about technology and not politics.
> THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
Its fitness for any particular purpose was expressly disclaimed, in all caps.
I'm not sure what people think they did wrong here. You're allowed (and should be allowed) to publish malware, it is up to consumers to not install software they don't want to run.
What more warning could they have possibly posted beyond this one?