Severity
High
Short Description
This package is a joke, parody, or includes undocumented or hidden behavior unrelated to its primary function.
Suggestion
Consider that consuming this package may come along with functionality unrelated to its primary purpose.
Protestware is software modified by its author with legitimate access for the purpose of making a statement or raising awareness. Unless the author is going for a scorched earth approach, the protest is usually designed to coexist with the software's intended functionality.
Protestware walks a fine line on the border of malware. When the embedded content or code’s behavior starts to interfere with the intended functionality or user experience of the software, or performs actions without the user’s consent, it crosses into malware territory.
Because of the immediate and unintended disruption protestware can have on open source supply chains, Socket’s AI-powered threat detection flags protestware/troll packages as a high severity risk:
This package is a joke, parody, or includes undocumented or hidden behavior unrelated to its primary function.
// Example for package.json "dependencies": { "some-library": "1.2.3" }This alert is triggered by a list of troll packages that Socket maintains. When one shows up in our AI threat feed, it is verified by a human researcher before being flagged as Protestware.