• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Ukraine invasion

Russia’s largest bank tells its clients to delay downloading software updates after ‘protestware’ attacks target Russian users

Nicholas Gordon
By
Nicholas Gordon
Nicholas Gordon
Asia Editor
Down Arrow Button Icon
Nicholas Gordon
By
Nicholas Gordon
Nicholas Gordon
Asia Editor
Down Arrow Button Icon
March 22, 2022, 7:07 AM ET

Sberbank, Russia’s largest bank, is advising its customers to delay software updates after a “protestware” attack targeted Russian and Belarusian users, and threatened to delete their files.

So-called protestware is when an activist programmer—or “hacktivist”—inserts malicious content into a library of open-source code in order to make a political statement. The effects of a protestware attack can spread very quickly across numerous computer systems, because many programers rely on open-source libraries to create software. Following Russia’s invasion of Ukraine, some hacktivists have used the tool to campaign against Russia.

Between March 7 and 8, a programmer using the handle RIAEvangelist wrote an update to node-ipc—a common piece of open-source code that other programmers frequently use when writing systems software. The malicious update executed code that scans users’ IP address when they download node-ipc. If the IP address comes from Russia or Belarus, the code would delete all of the user’s system files and replace them with a heart emoji.

RIAEvangelist quickly removed the malicious code after software engineering forum GitHub flagged the virus as a critical vulnerability, yet followed up with a new attack—titled “peacenotwar”—that would save a text file with an antiwar message on a user’s computer.

Sberbank didn’t say it had fallen victim to the attack, but the bank decided to warn its clients about the threat of malicious code being “embedded in freely distributed libraries used for software development.” The bank advised its customers to either avoid updating computer programs or to manually check the source code to ensure that no malicious updates had been included.

Advocates of open-source software coding have strongly criticized protestware, and the updates to node-ipc in particular, saying it undermines trust in the open-source system. Because of how integral open-source code is to every computer system, the fallout from a protestware attack can also be unpredictable and cause massive collateral damage.

On GitHub, one user claiming to work for an American nongovernment organization alleged that the malicious node-ipc update had deleted evidence of Russian war crimes in Ukraine from its Belarus-based server. The post was later withdrawn, and no NGO has come forward to substantiate the claim.

“Protestware” is also a reminder that many open-source projects—which act as the backbone for countless computer systems—are controlled, maintained, and updated by individual programmers, rather than professional organizations. The node-ipc attack was created by the individual responsible for maintaining its code, rather than an external attack from a third party. 

“You have to trust the people that you’re getting the components from,” Brian Fox, CTO of enterprise software company Sonatype, told SC Media. 

Never miss a story: Follow your favorite topics and authors to get a personalized email with the journalism that matters most to you.

About the Author
Nicholas Gordon
By Nicholas GordonAsia Editor
LinkedIn iconTwitter icon

Nicholas Gordon is an Asia editor based in Hong Kong, where he helps to drive Fortune’s coverage of Asian business and economics news.

See full bioRight Arrow Button Icon
0

Most Popular

placeholder alt text
Economy
Two months into the new fiscal year and the U.S. government is already spending more than $10 billion a week servicing national debt
By Eleanor PringleDecember 4, 2025
10 hours ago
placeholder alt text
North America
Jeff Bezos and Lauren Sánchez Bezos commit $102.5 million to organizations combating homelessness across the U.S.: ‘This is just the beginning’
By Sydney LakeDecember 2, 2025
2 days ago
placeholder alt text
Economy
Ford workers told their CEO 'none of the young people want to work here.' So Jim Farley took a page out of the founder's playbook
By Sasha RogelbergNovember 28, 2025
6 days ago
placeholder alt text
Success
‘Godfather of AI’ says Bill Gates and Elon Musk are right about the future of work—but he predicts mass unemployment is on its way
By Preston ForeDecember 4, 2025
6 hours ago
placeholder alt text
North America
Anonymous $50 million donation helps cover the next 50 years of tuition for medical lab science students at University of Washington
By The Associated PressDecember 2, 2025
2 days ago
placeholder alt text
Economy
Scott Bessent calls the Giving Pledge well-intentioned but ‘very amorphous,’ growing from ‘a panic among the billionaire class’
By Nick LichtenbergDecember 3, 2025
1 day ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.