Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    BTC YTD performance from 2 to sleep but 308,709x more returns since 2011

    August 10, 2025

    60 malicious ruby gems download 275,000 times stolen credibility

    August 10, 2025

    Asus Vivobook S16 Refresh in India with Snapdragon X Series Processor: Price, Specification

    August 10, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»60 malicious ruby gems download 275,000 times stolen credibility
    Security

    60 malicious ruby gems download 275,000 times stolen credibility

    PineapplesUpdateBy PineapplesUpdateAugust 10, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    60 malicious ruby gems download 275,000 times stolen credibility
    Share
    Facebook Twitter LinkedIn Pinterest Email

    60 malicious ruby gems download 275,000 times stolen credibility

    Targeting developer accounts, sixty malicious ruby gems with credential-chori codes have been downloaded from March 2023 more than 275,000 times.

    The malicious ruby gems were discovered by the socket, which reports that they have targeted South Korean users mainly of automation tools for Instagram, Ticketkok, Twitter/X, Telegram, Navar, WordPress and Kakao.

    RubyGems is the official package manager for ruby programming language, which enables the distribution, installation and management of ruby libraries, known as gems, much more for JavaScript Pypi for NPM or Python for JavaScript.

    In this campaign, malicious gems were published on rubygems.org under various surnames for years. Objectionable publishers are zones, novon, quonsoonje and desert, which spread activity on many accounts and make the activity hard to trace and block.

    Can be found in a complete list of malicious packages Socut reportBut there are some notable cases of misleadically nominated or typoscated package:

    • WordPress-style automater: wp_posting_duo, wp_posting_zon
    • Telegram-style bots: tg_send_duo, tg_send_zon
    • SEO/Backlink Tools: Backlink_zone, Back_duo
    • Blog platforms mimics: nblog_duo, nblog_zon, tblog_duopack, tblog_zon
    • NAVER CAFĂ© Interaction Tool: Cafe_Basics (_duo), cafe_buy (_duo), cafe_bey, *_blog_comment, *_cafe_comment

    All 60 gems highlighted in the socket report presents a graphical user interface (GUI) that is valid, as well as advertised functionality.

    In practice, however, they act as a fishing tools, exfiltrate credentials users, who enter the Hardcode Command-And-Control (C2) addresses (Programzon (.) Com, appspace () kr, marketingduo (.) Co (.) KR (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr (.) Kr.

    Malibly code snipyt present in 60 gems
    Malibly code snipyt present in 60 gems
    Source: socket

    The chopped data includes user names and passwords, device for fingerprinting and package names for expedition display tracking.

    In some cases, equipment reacts with a fake success or failure message, although no real login or API calls are made for real service.

    The socket has found credential logs on the dark-dark dark markets that appear to be obtained from these gems, which is connected to a suspected marketing tool site attacker, based on interaction with MarketingDuo (.) Cum (.) KR.

    Log related to infostealer campaign
    Log related to infostealer campaign
    Source: socket

    Researchers say that at least 16 of the 60 malicious ruby gems are available, although they have reported all of them to the rubies team on the search.

    Attacks of the supply chain on rubygems are not unprecedented, and they have been running for many years.

    In June, the socket reports another case of malicious ruby gems, which types Fastlane, a legitimate open-source plugin that acts as an automation tool for mobile app developers, especially the telegram bot developers.

    Developers should check the libraries that they are for sources from the open-source repository, such as for signs of suspected codes, which consider publisher’s reputation and release history, and lock dependence to ‘known to be safe’.


    Picus Red Report 2025

    Malware targeting password stores increased 3x as the attackers secretly carried out the perfect history landscape, infiltrated and exploited important systems.

    Search for the top 10 Metter Att & CK techniques behind the 93% attacks and how to defend them.

    credibility Download gems malicious ruby stolen times
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAsus Vivobook S16 Refresh in India with Snapdragon X Series Processor: Price, Specification
    Next Article BTC YTD performance from 2 to sleep but 308,709x more returns since 2011
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Google Data Brech confirms potential Google advertising customers information

    August 9, 2025
    Security

    Durch Datenlecks Verurachte Kosten Sind Gefallen

    August 9, 2025
    Security

    How you are charging your tablet, slowly killing it – to avoid 3 ways (and correctly)

    August 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    BTC YTD performance from 2 to sleep but 308,709x more returns since 2011

    August 10, 2025

    60 malicious ruby gems download 275,000 times stolen credibility

    August 10, 2025

    Asus Vivobook S16 Refresh in India with Snapdragon X Series Processor: Price, Specification

    August 10, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.