Maintainer Brian McManus's account was compromised via a weak/reused password; he had not logged into RubyGems for years. Malicious version waited for a production environment, fetched a payload from Pastebin, and achieved full RCE. Only 537 downloads before removal. Discovered during manual dependency review at Epion Health.
PACKAGE_STALE_RELEASE + SOURCE_SINGLE_CONTRIBUTOR flagged as abandoned before takeover; PACKAGE_ACTIVE_MALWARE at install
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_STALE_RELEASE + SOURCE_SINGLE_CONTRIBUTOR flagged as abandoned before takeover; PACKAGE_ACTIVE_MALWARE at install |
| Socket | Partial | Limited coverage for small RubyGems packages |
| Snyk | Missed | No malware detection |
| Sonatype (Nexus) | Missed | Weak PyPI/RubyGems coverage for dormant packages |
| Black Duck | Missed | No malware detection |
| Endor Labs | Missed | No malware detection |