Menu

Post image 1
Post image 2
1 / 2
0

RubyGems Suspends New Signups Following Mass Malicious Package Injection

DEV Community·BeyondMachines·20 days ago
#ECu526NV
Reading 0:00
15s threshold
Cover image for RubyGems Suspends New Signups Following Mass Malicious Package Injection

Summary

RubyGems suspended new account registrations after attackers uploaded hundreds of malicious packages containing exploits to the repository.

Take Action:

If you're a Ruby developer, audit your Gemfile.lock for any unfamiliar or recently added dependencies and run bundle-audit to scan for known vulnerabilities. Avoid installing or updating gems until RubyGems confirms the cleanup is complete, and treat any new dependency added in the last few days with extra suspicion.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Read More