Definition
Protestware is open-source software that its own maintainer deliberately changes to make a protest or political statement, ranging from printing a message to breaking the package or damaging files on certain machines.
Notable examples
- colors and faker (January 2022): the author pushed versions with an infinite loop of garbage output, breaking thousands of projects, in protest at unpaid use by large companies.
- node-ipc (March 2022): versions added code that overwrote files on machines with Russian or Belarusian IP addresses (CVE-2022-23812), and a dependency that dropped a peace message on the desktop.
Protestware is hard to anticipate because the publisher is the legitimate maintainer: no account was stolen and no name was squatted.
How to protect your builds
- Pin exact versions with a lockfile, so a new release only arrives through a reviewed update.
- Review release diffs for unexpected behavior such as geolocation lookups, file writes outside the package or new dependencies.
- Scan new versions before upgrading. Code that deletes or overwrites files is flagged as high risk in Togoder Security reports.
Frequently asked questions
Is protestware malware?
When it damages data or systems, it behaves like malware regardless of motive, and registries and advisory databases treat destructive versions as malicious.