Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. RubyGems Suspends New Signups Following Mass Malicious Package Injection

RubyGems Suspends New Signups Following Mass Malicious Package Injection

Scheduled Pinned Locked Moved Uncategorized
cybersecurityinfosecincidentransomware
3 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • beyondmachines1@infosec.exchangeB This user is from outside of this forum
    beyondmachines1@infosec.exchangeB This user is from outside of this forum
    beyondmachines1@infosec.exchange
    wrote last edited by
    #1

    RubyGems Suspends New Signups Following Mass Malicious Package Injection

    RubyGems suspended new account registrations after attackers uploaded hundreds of malicious packages containing exploits to the repository.

    **If you're a Ruby developer, audit your Gemfile.lock for any unfamiliar or recently added dependencies and run bundle-audit to scan for known vulnerabilities. Avoid installing or updating gems until RubyGems confirms the cleanup is complete, and treat any new dependency added in the last few days with extra suspicion.**
    #cybersecurity #infosec #incident #ransomware
    https://beyondmachines.net/event_details/rubygems-suspends-new-signups-following-mass-malicious-package-injection-x-e-f-z-2/gD2P6Ple2L

    jschwart@mas.toJ 1 Reply Last reply
    0
    • beyondmachines1@infosec.exchangeB beyondmachines1@infosec.exchange

      RubyGems Suspends New Signups Following Mass Malicious Package Injection

      RubyGems suspended new account registrations after attackers uploaded hundreds of malicious packages containing exploits to the repository.

      **If you're a Ruby developer, audit your Gemfile.lock for any unfamiliar or recently added dependencies and run bundle-audit to scan for known vulnerabilities. Avoid installing or updating gems until RubyGems confirms the cleanup is complete, and treat any new dependency added in the last few days with extra suspicion.**
      #cybersecurity #infosec #incident #ransomware
      https://beyondmachines.net/event_details/rubygems-suspends-new-signups-following-mass-malicious-package-injection-x-e-f-z-2/gD2P6Ple2L

      jschwart@mas.toJ This user is from outside of this forum
      jschwart@mas.toJ This user is from outside of this forum
      jschwart@mas.to
      wrote last edited by
      #2

      @beyondmachines1 does this apply only if you missed switching over to gem.coop or is that affected as well?

      beyondmachines1@infosec.exchangeB 1 Reply Last reply
      0
      • jschwart@mas.toJ jschwart@mas.to

        @beyondmachines1 does this apply only if you missed switching over to gem.coop or is that affected as well?

        beyondmachines1@infosec.exchangeB This user is from outside of this forum
        beyondmachines1@infosec.exchangeB This user is from outside of this forum
        beyondmachines1@infosec.exchange
        wrote last edited by
        #3

        @jschwart no reports on gem.coop.
        RubyGems were quite loud about this, and we can't find whether gem.coop uses the same files published to RubyGems...

        Safest approach is to still do the same level of review as if gem.coop was attacked.

        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups