Campaign · Open Source · · 5 days

faker.js and colors.js sabotage broke apps

The faker.js and colors.js sabotage was a paired maintainer protest that broke two widely used npm libraries in early January 2022.

Draws together 2 incidents across 2 packages

The faker.js and colors.js failures came from the same place: maintainer control. No outside attacker needed to break accounts or infrastructure. The author controlled the projects and used that authority to publish or push code that downstream systems consumed as ordinary updates.

faker.js was pushed into an "endgame" state and npm received version 6.6.6, a package that no longer behaved like the widely used data generator developers expected. colors.js received releases that printed protest text and entered an infinite loop.

The damage was operational. Applications broke during install, startup, or test runs because a small transitive package had become active failure code. The event showed that maintainer sabotage is still a supply-chain failure when the official project channel carries the change.

Recovery was social as much as technical. The community forked faker under new stewardship, package managers and maintainers pinned or rolled back dependencies, and the incident became a standing example of why tiny libraries with huge dependency graphs still need release discipline.

Incidents in this campaign

  1. faker.js npm maintainer sabotage broke apps
  2. colors.js npm maintainer sabotage broke apps

Appendix · Affected packages

faker.js 2022-01-04 to 2022-01-09
6.6.6
colors.js 2022-01-07 to 2022-01-09
1.4.11.4.21.4.44-liberty-2

Samples and hashes sit on each incident page, linked above

References

  1. Dev corrupts npm libs colors and faker breaking thousands of appsbleepingcomputer.com
  2. Open source npm packages colors and faker sabotagedsnyk.io

Source record: oss/campaigns/faker-colors-sabotage-2022/meta.yaml