Rubygems typosquatting malware

As developers increasingly embrace off-the-shelf software components into their apps and services, threat actors are abusing open-source repositories such as RubyGems to distribute malicious packages, intended to compromise their computers or backdoor software projects they work on.

In the latest research shared with The Hacker News, cybersecurity experts at ReversingLabs revealed over 700 malicious gems — packages written in Ruby programming language — that supply chain attackers were caught recently distributing through the RubyGems repository.

The malicious campaign leveraged the typosquatting technique where attackers uploaded intentionally misspelled legitimate packages in hopes that unwitting developers will mistype the name and unintentionally install the malicious library instead.

ReversingLabs said the typosquatted packages in question were uploaded to RubyGems between February 16 and February 25, and that most of them have been designed to secretly steal funds by redirecting cryptocurrency transactions to a wallet address under the attacker’s control.

In other words, this particular supply chain attack targeted Ruby developers with Windows systems who also…

http://feedproxy.google.com/~r/TheHackersNews/~3/fBQujiDykNI/rubygem-typosquatting-malware.html

About Author
Edvis
View All Articles
Check latest article from this author !
SonicWall Vulnerability Under Active Attack
New Apple CarPlay Release Date Remains Unknown
Trump Backs Crypto Expansion

Trump Backs Crypto Expansion

January 25, 2025

Leave a Reply

Related Posts