The maintainer of the node-ipc package, a node.js module for local and remote inter-process communication, added code to some of its nested dependencies, resulting in files on computers with Russian or Belarussian IPs being wiped, a security firm claims.