When the Threat Is the Maintainer
The npm registry's dependency model rests on a compact between library authors and the millions of projects that pull their work. Two incidents, separated by four years, broke that compact in different ways — and exposed how little the ecosystem distinguishes between a maintainer who turns malicious, a maintainer who burns out, and a maintainer who decides to stop playing along.
In late 2018, a package called event-stream was downloaded roughly two million times per week. Its original author, Dominic Tarr, had largely moved on from the project and, when a new contributor offered to take over maintenance, handed it across with minimal due diligence. The new maintainer, whose real identity was never established, added a dependency — flatmap-stream — to the package. That dependency carried an encrypted payload, activated only when it detected a specific Bitcoin wallet application called Copay, built by BitPay. The attack was a supply-chain attack aimed not at the ecosystem at large but at one target, hidden inside a generic utility that happened to sit in Copay's dependency tree. It remained undetected for roughly two months before a developer noticed an anomaly in a minified bundle.
The event-stream incident revealed three compounding problems at once: the ease with which maintainership of a high-traffic package could be transferred without scrutiny; the invisibility of transitive dependencies to most downstream consumers; and the absence, at the time, of any provenance attestation that would link a published artefact back to a verified source commit. npm's advisory system flagged the payload after discovery, but the window of exposure had already closed around a specific, real-money target.
Protest as Sabotage
The colors and faker incidents in January 2022 operated on entirely different logic. Marak Squires, who maintained both packages — colors.js providing terminal string colouring, faker.js generating synthetic test data — published versions that deliberately broke their own functionality. The colors update introduced an infinite loop that printed "LIBERTY LIBERTY LIBERTY" to the terminal; faker was published as a broken stub. Both packages carried combined weekly downloads numbering in the tens of millions at the time. Squires had previously published a public note stating that he was done providing free work to corporations generating billions of dollars from his libraries without compensation.
This was not a covert attack. It was a public act of maintainer protest — closer in nature to a strike than to sabotage — carried out with full transparency about its motivation. The response from the ecosystem was telling: GitHub, which hosts the repositories, took the unusual step of suspending Squires' account, and the ecosystem moved to roll back to earlier clean releases, restoring the package to a version Squires had not authorised. That decision drew immediate criticism from parts of the open-source community, who argued it subordinated maintainer rights to downstream convenience. Others argued that a library distributed as a stable dependency carries an implicit contract that a unilateral break violates regardless of the grievance behind it.
- CHRONOLOGYAS RECORDED
- October–November 2018event-stream backdoor inserted and active; detected November 2018
- January 2022Marak Squires publishes breaking versions of colors.js and faker.js
- January 2022GitHub reverts faker.js repository to a prior clean state without author consent
The incident made the funding argument viscerally concrete in a way that position papers had not managed. Denis Pushkarev's documented accounting of the core-js funding problem had been largely abstract; Squires' protest was impossible to ignore in a CI pipeline.

What the Two Failures Share
Different as the motivations were, the event-stream attack and the colors/faker protest share structural parents: a maintenance model in which individual contributors, often unpaid, hold unilateral power over packages embedded in critical infrastructure, and a registry architecture in which publishing a new version requires no external review. The attack exploited the first; the protest demonstrated the second.
Responses to the event-stream incident eventually fed into work on Sigstore and SBOM mandates — mechanisms designed to make the provenance of published packages verifiable, so that an unexpected dependency addition would be detectable before execution rather than after. Neither tool addresses the underlying economics that produce maintainer burnout, which is the condition that made both Tarr's casual transfer and Squires' exhaustion possible in the first place. The plumbing can be audited, signed, and cross-referenced; it cannot be paid by any of those means alone.
