• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Ukraine invasion

Russia’s largest bank tells its clients to delay downloading software updates after ‘protestware’ attacks target Russian users

Nicholas Gordon
By
Nicholas Gordon
Nicholas Gordon
Asia Editor
Down Arrow Button Icon
Nicholas Gordon
By
Nicholas Gordon
Nicholas Gordon
Asia Editor
Down Arrow Button Icon
March 22, 2022, 7:07 AM ET

Sberbank, Russia’s largest bank, is advising its customers to delay software updates after a “protestware” attack targeted Russian and Belarusian users, and threatened to delete their files.

So-called protestware is when an activist programmer—or “hacktivist”—inserts malicious content into a library of open-source code in order to make a political statement. The effects of a protestware attack can spread very quickly across numerous computer systems, because many programers rely on open-source libraries to create software. Following Russia’s invasion of Ukraine, some hacktivists have used the tool to campaign against Russia.

Between March 7 and 8, a programmer using the handle RIAEvangelist wrote an update to node-ipc—a common piece of open-source code that other programmers frequently use when writing systems software. The malicious update executed code that scans users’ IP address when they download node-ipc. If the IP address comes from Russia or Belarus, the code would delete all of the user’s system files and replace them with a heart emoji.

RIAEvangelist quickly removed the malicious code after software engineering forum GitHub flagged the virus as a critical vulnerability, yet followed up with a new attack—titled “peacenotwar”—that would save a text file with an antiwar message on a user’s computer.

Sberbank didn’t say it had fallen victim to the attack, but the bank decided to warn its clients about the threat of malicious code being “embedded in freely distributed libraries used for software development.” The bank advised its customers to either avoid updating computer programs or to manually check the source code to ensure that no malicious updates had been included.

Advocates of open-source software coding have strongly criticized protestware, and the updates to node-ipc in particular, saying it undermines trust in the open-source system. Because of how integral open-source code is to every computer system, the fallout from a protestware attack can also be unpredictable and cause massive collateral damage.

On GitHub, one user claiming to work for an American nongovernment organization alleged that the malicious node-ipc update had deleted evidence of Russian war crimes in Ukraine from its Belarus-based server. The post was later withdrawn, and no NGO has come forward to substantiate the claim.

“Protestware” is also a reminder that many open-source projects—which act as the backbone for countless computer systems—are controlled, maintained, and updated by individual programmers, rather than professional organizations. The node-ipc attack was created by the individual responsible for maintaining its code, rather than an external attack from a third party. 

“You have to trust the people that you’re getting the components from,” Brian Fox, CTO of enterprise software company Sonatype, told SC Media. 

Never miss a story: Follow your favorite topics and authors to get a personalized email with the journalism that matters most to you.

About the Author
Nicholas Gordon
By Nicholas GordonAsia Editor
LinkedIn iconTwitter icon

Nicholas Gordon is an Asia editor based in Hong Kong, where he helps to drive Fortune’s coverage of Asian business and economics news.

See full bioRight Arrow Button Icon
0

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Most Popular

placeholder alt text
Newsletters
The oil CEO who stood up to Trump is a follower of the disciplined 'Exxon way' and has a history of blunt statements
By Jordan BlumJanuary 13, 2026
1 day ago
placeholder alt text
Tech
Elon Musk asked people to upload their medical data to X so his AI company could learn to interpret MRIs and CT scans
By Sasha RogelbergJanuary 11, 2026
3 days ago
placeholder alt text
Economy
Treasury spent $276 billion in interest on the national debt in the final three months of 2025, says the CBO—up $30 billion from a year prior
By Eleanor PringleJanuary 12, 2026
2 days ago
placeholder alt text
Economy
The longer the Supreme Court delays its tariff decision, the better it is for President Trump
By Jim EdwardsJanuary 13, 2026
23 hours ago
placeholder alt text
Success
Despite his $2.6 billion net worth, MrBeast says he’s having to borrow cash and doesn’t even have enough money in his bank account to buy McDonald’s
By Emma BurleighJanuary 13, 2026
18 hours ago
placeholder alt text
AI
'Godfather of AI' says the technology will create massive unemployment and send profits soaring — 'that is the capitalist system'
By Jason MaJanuary 12, 2026
2 days ago

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.