- Joined
- Jul 22, 2017
(gonna be a bit redundant because I already wrote up some stuff)
Brandon Nozaki Miller added a poorly obfuscated script to recursively overwrite all files on the system with a heart emoji if it gets a Russian or Belarus IP from some API.
Not only is this unethical and criminal, GeoIP information is totally unreliable. For example the GeoIP information of KFcc is wrong and reports a different country than where the servers actually exist. It appears based on opened issues that this is affecting Chinese users, probably because GeoIP information is not reliable. Maybe people just have servers in Russia or Belarus. What a fucking retard.
As part of damage control he keeps telling everyone "oh it was just this 'peace-not-war' thing it doesn't really do anything bad". But he doesn't address the fact he added his own little script that actually overwrite files.
Don't get confused, these are two different actions. Someone took the time to de-obfuscate and comment on the more malicious code he added: https://gist.github.com/ckcr4lyf/6d96c2bf42ec31c6362053ea275d80d5 (https://archive.ph/GPJeG )

Downstream VueJS issue: https://github.com/vuejs/vue-cli/issues/7054 (https://archive.ph/7qJ3t)
Malicious Code: https://github.com/RIAEvangelist/no...08352038b2204f0e7633449580/dao/ssl-geospec.js (https://archive.ph/n8oBX)
Just a sample of all the fun issues at https://github.com/RIAEvangelist/node-ipc/issues


Westoid News (doesn't mention the deletion script): https://www.itnews.com.au/news/prot...ependency-labelled-supply-chain-attack-577488 (https://archive.ph/PCzJ4 )
Chinese Discussion: https://www.zhihu.com/question/522144107 (https://archive.ph/jeNML )
Brandon Nozaki Miller added a poorly obfuscated script to recursively overwrite all files on the system with a heart emoji if it gets a Russian or Belarus IP from some API.
Not only is this unethical and criminal, GeoIP information is totally unreliable. For example the GeoIP information of KFcc is wrong and reports a different country than where the servers actually exist. It appears based on opened issues that this is affecting Chinese users, probably because GeoIP information is not reliable. Maybe people just have servers in Russia or Belarus. What a fucking retard.
As part of damage control he keeps telling everyone "oh it was just this 'peace-not-war' thing it doesn't really do anything bad". But he doesn't address the fact he added his own little script that actually overwrite files.
Don't get confused, these are two different actions. Someone took the time to de-obfuscate and comment on the more malicious code he added: https://gist.github.com/ckcr4lyf/6d96c2bf42ec31c6362053ea275d80d5 (https://archive.ph/GPJeG )

Downstream VueJS issue: https://github.com/vuejs/vue-cli/issues/7054 (https://archive.ph/7qJ3t)
Malicious Code: https://github.com/RIAEvangelist/no...08352038b2204f0e7633449580/dao/ssl-geospec.js (https://archive.ph/n8oBX)
Just a sample of all the fun issues at https://github.com/RIAEvangelist/node-ipc/issues


Westoid News (doesn't mention the deletion script): https://www.itnews.com.au/news/prot...ependency-labelled-supply-chain-attack-577488 (https://archive.ph/PCzJ4 )
Chinese Discussion: https://www.zhihu.com/question/522144107 (https://archive.ph/jeNML )
https://twitter.com/electricCowboyR (https://archive.ph/CFqJL)
https://twitter.com/electricCowboyR/status/1503828635601448960 (https://archive.ph/HSJNe)
https://hackaday.io/RIAEvangelist (https://archive.ph/p7I8l)
https://imgur.com/user/BrandonNozakiMiller (https://archive.ph/fGpVH)
https://stackoverflow.com/users/1150771/brandon-nozaki-miller (https://archive.ph/rLQhK)
https://www.behance.net/RIAEvangelist/info (https://archive.ph/SS2zM)
https://www.buzzfeed.com/RIAEvangelist (https://archive.ph/fhj4F)
https://www.facebook.com/RIAEvangelist (https://archive.ph/ySOaD)
https://www.facebook.com/RIAEvangelist/about (https://archive.ph/ulyzs)
https://www.facebook.com/RIAEvangelist/friends (https://archive.ph/U1Txm)
https://www.youtube.com/brandonnozakimiller (https://archive.ph/fOaTN )
https://www.linkedin.com/in/electriccowboy/ (unarchivable)
https://www.patreon.com/BrandonNozakiMiller/creators (https://archive.ph/5lNjL )
https://www.quora.com/profile/Brandon-Nozaki-Miller (https://archive.ph/zvGeA)
https://www.reddit.com/user/RIAEvangelist (https://archive.ph/R3sGi)
https://www.similarplay.com/diginowit/ppihc_pikes_peak_race/apps/com.brandondiginow.it.pikespeak2014 (https://archive.ph/knUNB)
https://www.indiegogo.com/individuals/19433827/campaigns (https://archive.ph/ocEnG)
https://www.indiegogo.com/projects/diginow-supercharger-v2-5-mass-production#/ (https://archive.ph/OSDNJ)
https://www.indiegogo.com/projects/nissan-leaf-tesla-faster-level-2#/ (https://archive.ph/fyDdM)
https://www.instagram.com/electriccowboyracing/ (https://archive.ph/qCsWw)
https://bugs.chromium.org/p/chromium/issues/detail?id=431795 (https://archive.ph/ja0wb)
https://twitter.com/electricCowboyR/status/1503828635601448960 (https://archive.ph/HSJNe)
https://hackaday.io/RIAEvangelist (https://archive.ph/p7I8l)
https://imgur.com/user/BrandonNozakiMiller (https://archive.ph/fGpVH)
https://stackoverflow.com/users/1150771/brandon-nozaki-miller (https://archive.ph/rLQhK)
https://www.behance.net/RIAEvangelist/info (https://archive.ph/SS2zM)
https://www.buzzfeed.com/RIAEvangelist (https://archive.ph/fhj4F)
https://www.facebook.com/RIAEvangelist (https://archive.ph/ySOaD)
https://www.facebook.com/RIAEvangelist/about (https://archive.ph/ulyzs)
https://www.facebook.com/RIAEvangelist/friends (https://archive.ph/U1Txm)
https://www.youtube.com/brandonnozakimiller (https://archive.ph/fOaTN )
https://www.linkedin.com/in/electriccowboy/ (unarchivable)
https://www.patreon.com/BrandonNozakiMiller/creators (https://archive.ph/5lNjL )
https://www.quora.com/profile/Brandon-Nozaki-Miller (https://archive.ph/zvGeA)
https://www.reddit.com/user/RIAEvangelist (https://archive.ph/R3sGi)
https://www.similarplay.com/diginowit/ppihc_pikes_peak_race/apps/com.brandondiginow.it.pikespeak2014 (https://archive.ph/knUNB)
https://www.indiegogo.com/individuals/19433827/campaigns (https://archive.ph/ocEnG)
https://www.indiegogo.com/projects/diginow-supercharger-v2-5-mass-production#/ (https://archive.ph/OSDNJ)
https://www.indiegogo.com/projects/nissan-leaf-tesla-faster-level-2#/ (https://archive.ph/fyDdM)
https://www.instagram.com/electriccowboyracing/ (https://archive.ph/qCsWw)
https://bugs.chromium.org/p/chromium/issues/detail?id=431795 (https://archive.ph/ja0wb)
This private information is unavailable to guests due to policies enforced by third-parties.
Last edited: