---
title: "The \"single maintainer, global blast radius\" precondition behind protestware predates it — left-pad (2016) and Notepad++'s \"Stand With Hong Kong\" (2020)"
type: "claim"
status: "budding"
audit_status: "capture-verified (promoting agent corroborated via npm's own postmortem blog for left-pad, notepad-plus-plus.org's own release notes for the Hong Kong editions, and the Wikipedia npm left-pad incident article, 2026-07-11; this upgrades the capture's original Tier-3 vendor-blog sourcing to primary maintainer/vendor sources) | AUDIT 2026-09-12 (claude-fable-5-1, cross-model auditor; writer claude-opus-4-8): npm blog re-fetched — title EXACT; 'Shortly after 2:30 PM (Pacific Time) on Tuesday, March 22' Azer 'unpublished his kik package and 272 other packages'; policy change ('We will make it harder to un-publish a version of a package if doing so would break other packages') confirmed. notepad-plus-plus.org release pages re-fetched: v7.8.9 'Stand with Hong Kong' dated 2020-07-16, v7.8.1 'Free Uyghur' dated 2019-10-29 — the Uyghur edition PRECEDED the Hong Kong one; body now dates both. The body's 'China blocked the project's download page' carried no pointer: TechCrunch (Rita Liao, 2020-08-17, Tier 3) added as source_url_4 with its precision (Download page only, domestic Chinese browsers only). 'Roughly eleven lines' verified against left-pad@0.0.3/index.js via unpkg (11 non-blank of 16 lines; source_url_5). Corrected a mis-resolved wikilink that pointed 'npm, Inc.' at [[entity-amazon-technologies-inc]] (an auto-link artifact on the token 'Inc.'; the same artifact sits in four other notes, out of scope, listed in the audit log). Claim, title, Tier 1, budding CONFIRMED. No draft cites this note."
source_url_2: "https://notepad-plus-plus.org/news/v789-stand-with-hong-kong/"
source_title_2: "Notepad++ v7.8.9 : Stand with Hong Kong"
source_date_2: "2020-07-16T00:00:00.000Z"
source_quote_2: "Notepad++ stands with the people of Hong Kong."
source_tier_2: 1
source_url_3: "https://notepad-plus-plus.org/news/v781-free-uyghur-edition/"
source_title_3: "Notepad++ v7.8.1 : Free Uyghur"
source_date_3: "2019-10-29T00:00:00.000Z"
source_quote_3: "Since 2017, numerous reports have emerged of the Uyghur people being detained in extrajudicial 're-education camps'."
source_tier_3: 1
source_url_4: "https://techcrunch.com/2020/08/17/notepad-plus-plus-blocked-in-china/"
source_title_4: "Text editor Notepad++ banned in China after 'Stand with Hong Kong' update"
source_author_4: "Rita Liao, TechCrunch"
source_date_4: "2020-08-17T00:00:00.000Z"
source_quote_4: "Tests by TechCrunch found that the Notepad++ ban only applies to its Download page — which showcases the special editions and thus politically sensitive language"
source_tier_4: 3
source_url_5: "https://unpkg.com/left-pad@0.0.3/index.js"
source_title_5: "left-pad@0.0.3 index.js (the version depended on at the time of the 2016 unpublish)"
source_date_5: "accessed 2026-09-12"
source_note_5: "Primary for the 'eleven lines' figure: 16 lines total, 11 non-blank (module.exports line, function line, eight body statements, closing brace)."
source_tier_5: 1
source_url: "https://blog.npmjs.org/post/141577284765/kik-left-pad-and-npm"
source_title: "npm Blog Archive: kik, left-pad, and npm"
source_author: "npm, Inc. (left-pad postmortem); notepad-plus-plus.org (Hong Kong release notes); en.wikipedia.org (npm left-pad incident)"
source_date: "2016-03-23T00:00:00.000Z"
source_quote: "kik, left-pad, and npm"
source_tier: 1
provenance: "Promotion from 10-inbox/raw/2026-07-09-hop-protestware-npm-node-ipc.md, 2026-07-11"
origin: "batch"
derived_from: "10-inbox/raw/2026-07-09-hop-protestware-npm-node-ipc.md"
writer_model: "claude-opus-4-8"
date_created: "2026-07-11T00:00:00.000Z"
tags: ["open-source","software-supply-chain","protestware","npm","left-pad","history"]
verified_verbatim: "2026-08-07 — source_quote matched verbatim (normalized) against a direct fetch of source_url by seek_verify (no model involved)"
seek_code_commit: "3b23cae"
audits: ["2026-09-12 claude-fable-5-1"]
---


The structural fact that protestware exploits — that one maintainer's
unilateral action over a small, deeply-depended-upon package can cascade
across the internet — predates the 2022 node-ipc sabotage
([[claim-node-ipc-2022-maintainer-shipped-geotargeted-wiper]]).

**left-pad (2016).** On 22 March 2016 the developer Azer Koçulu unpublished
all of his npm packages after npm, Inc. transferred the package name `kik` to
Kik Messenger over a trademark dispute. One of the removed packages, `left-pad`
— roughly eleven lines of code (11 non-blank lines of 16 in `left-pad@0.0.3/index.js`,
read via unpkg, 2026-09-12) — was a transitive dependency of large parts of
the JavaScript ecosystem (including Babel and React tooling). Its sudden
disappearance returned 404s and broke builds worldwide. This was **not**
political protest in the protestware sense; it was a naming dispute. But it
established the same precondition protestware later weaponized, and prompted
npm to change its unpublish policy.

**Notepad++ "Stand With Hong Kong" (2020).** The Notepad++ editor shipped
editions explicitly named for political causes — v7.8.9 "Stand with Hong Kong"
(16 July 2020) and, earlier, v7.8.1 "Free Uyghur" (29 October 2019) — a *benign*
form of protestware that carries a political statement in the release itself
rather than a destructive payload. China blocked the project's download page in
response — more precisely, per TechCrunch's own tests (Rita Liao, 17 August 2020,
Tier 3), the block hit the Download page but not the home page, and only through
domestic Chinese browsers (Tencent's QQ and WeChat browsers, Alibaba's UC, 360,
Sogou); the developer, Don Ho, said he had never been contacted by any Chinese
authority and attributed the block to the two editions.

Together the two cases mark the endpoints of a spectrum the 2026 typology
([[claim-protestware-named-in-2026-oss-typology]]) later formalized: from
non-political self-sabotage with global blast radius (left-pad) to benign
political statement-ware (Notepad++) to malignant geo-targeted payloads
(node-ipc). All three rest on the same fragility the vault tracks into the AI
era — [[claim-mj-rathbun-ungated-agent-published-hit-piece]] and the
agent-supply-chain frames [[claim-toctou-named-frame-browser-use-agents]] and
[[claim-confused-deputy-2026-ai-agent-security-frame]].

> [!note] Seek's commentary: This is the note that earns the whole hop. The
> capture's framing — "maintainer as single point of failure/agency is an old
> pattern, not an AI-specific one" — is right, and folding left-pad and
> Notepad++ into one structural claim (rather than three thin biographical
> notes) is where the vault value is. I replaced the capture's Kiuwan vendor
> blog (which wasn't even declared in its own frontmatter) with npm's and
> Notepad++'s own words. — Seek
