It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
RubyGems maintainers pull packages RubyGems maintainers pull packages
FAQ Members List Calendar Search Today's Posts Mark Forums Read


RubyGems maintainers pull packages
Reply
 
Thread Tools
Old 23rd August 2019, 07:46   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,678
Stefan Mileschin Freshly Registered
Default RubyGems maintainers pull packages

11 Ruby libraries had a backdoor

Maintainers of the RubyGems package repository have pulled 18 malicious versions of 11 Ruby libraries that contained a backdoor mechanism and were caught inserting code that launched hidden cryptocurrency mining operations inside other people's Ruby projects.

The malicious code was discovered yesterday inside four versions of rest-client, an extremely popular Ruby library.

Dutch Ruby developer Jan Dintel said that the malicious code found in rest-client would collect and send the URL and environment variables of a compromised system to a remote server in Ukraine.

Depending on your setup this can include credentials of services that you use. for example database, payment service provider, Dintel said.

The code contained a backdoor mechanism that allowed the attacker to send a cookie file back to a compromised project, and allow the attacker to execute malicious commands. A subsequent investigation by the RubyGems staff discovered that this mechanism was being abused to insert cryptocurrency mining code.

RubyGems staff also uncovered similar code in 10 other projects. All the libraries, except rest-client, were created by taking another fully functional library, adding the malicious code, and then re-uploading it on RubyGems under a new name. All in all, all the 18 malicious library versions only managed to amass 3,584 downloads before being removed from RubyGems.
https://fudzilla.com/news/49258-ruby...-pull-packages
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
VW wants to ensure EVs are delivering your packages Stefan Mileschin WebNews 0 30th November 2018 13:54
Amazon can deliver packages to the inside of your car Stefan Mileschin WebNews 0 26th April 2018 12:07
Comcast is bundling Netflix into cable packages Stefan Mileschin WebNews 0 16th April 2018 09:48
Fan config: Does it matter? Testing push vs pull vs push/pull Stefan Mileschin WebNews 0 30th December 2016 08:53
Samsung builds 8GB LPDDR4 packages on its 10-nm process Stefan Mileschin WebNews 0 21st October 2016 11:22
Sky's Now TV Combo packages go on sale Stefan Mileschin WebNews 0 10th July 2016 14:23
How to Install and Manage Snap Packages on Ubuntu 16.04 LTS Stefan Mileschin WebNews 0 27th April 2016 07:15
Shyp will now deliver your eBay packages, with no fee Stefan Mileschin WebNews 0 3rd December 2015 07:13
PayPal now lets you pay for packages days after you order them Stefan Mileschin WebNews 0 4th November 2014 11:25

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 18:58.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO