Skip to content

Invalid SHA-256 for https://nodejs.org/dist/v22.22.1/node-v22.22.1.pkg #878

Description

@procr1337

https://nodejs.org/dist/v22.22.1/node-v22.22.1.pkg serves a file with SHA256 1fbe9cd7e9fdce6cf150bbe59cb97a426434f7fb217135d10124a62bfb697448

However https://nodejs.org/en/blog/release/v22.22.1 states ac8cb570db59cb399be96978c194f6c4fc91ffcf11a197ebd5461083c0cf1dfd as the correct checksum

Activity

  1. avivkeller commented on Mar 8, 2026

    @avivkeller
    Member

    cc @nodejs/release

  2. added theissue type on Mar 8, 2026
  3. aduh95 commented on Mar 8, 2026

    @aduh95
    Contributor

    @marco-ippolito any idea what might have happened?

  4. marco-ippolito commented on Mar 8, 2026

    @marco-ippolito
    Member

    no idea I haven't seen anything strange during the release other than the node.config.json artifact not being expected

  5. procr1337 commented on Mar 8, 2026

    @procr1337
    Author

    do you have the preimage to ac8cb570db59cb399be96978c194f6c4fc91ffcf11a197ebd5461083c0cf1dfd ?

  6. flakey5 commented on Mar 8, 2026

    @flakey5
    Member

    https://nodejs.org/dist/v22.22.1/SHASUMS256.txt also states sha ac8cb570db59cb399be96978c194f6c4fc91ffcf11a197ebd5461083c0cf1dfd

    Shasums of the files in dist-prod and dist-staging buckets match 1fbe9cd7e9fdce6cf150bbe59cb97a426434f7fb217135d10124a62bfb697448, but when grabbing it from direct.nodejs.org, it's ac8cb570db59cb399be96978c194f6c4fc91ffcf11a197ebd5461083c0cf1dfd

    Image
  7. flakey5 commented on Mar 8, 2026

    @flakey5
    Member

    cc @nodejs/build

  8. MattIPv4 commented on Mar 9, 2026

    @MattIPv4
    Member

    Pulled down both files on my mac:

    R2 macOS signature (1fbe9cd7e9fdce6cf150bbe59cb97a426434f7fb217135d10124a62bfb697448):

    Image

    Direct macOS signature (ac8cb570db59cb399be96978c194f6c4fc91ffcf11a197ebd5461083c0cf1dfd):

    Image

    Both are seen as properly signed, so this definitely doesn't seem malicious.

  9. MattIPv4 commented on Mar 9, 2026

    @MattIPv4
    Member

    👋 FYI, we've done a bunch more digging into this (full report over in nodejs/web-team#110), but the good news is that we're confident this was just the release process going slightly awry and generating this file twice.

    We've now updated the copy being served by production to be what is listed in the SHAs.

  10. avivkeller commented on Mar 9, 2026

    @avivkeller
    Member

    To iterate on Matt's statement, both files were created and signed by the Node.js Project, as shown in the screenshot's he provided, and are 100% safe for use.

    There was no compromise at any point, merely some release run mayhem.

  11. flakey5 commented on Mar 9, 2026

    @flakey5
    Member

    Thank you for reporting!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions