Account Takeover 2019 Incident #11 CVE-2019-13354

strong_password gem

Estimated Financial Impact
Limited (537 downloads)
Blast Radius
Dormant maintainer; Epion Health

What Happened

Maintainer Brian McManus's account was compromised via a weak/reused password; he had not logged into RubyGems for years. Malicious version waited for a production environment, fetched a payload from Pastebin, and achieved full RCE. Only 537 downloads before removal. Discovered during manual dependency review at Epion Health.

✓

Risk Guard: Caught

PACKAGE_STALE_RELEASE + SOURCE_SINGLE_CONTRIBUTOR flagged as abandoned before takeover; PACKAGE_ACTIVE_MALWARE at install

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_STALE_RELEASESOURCE_SINGLE_CONTRIBUTOR

How Every Tool Performed

1 Caught 1 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_STALE_RELEASE + SOURCE_SINGLE_CONTRIBUTOR flagged as abandoned before takeover; PACKAGE_ACTIVE_MALWARE at install
Socket Partial Limited coverage for small RubyGems packages
Snyk Missed No malware detection
Sonatype (Nexus) Missed Weak PyPI/RubyGems coverage for dormant packages
Black Duck Missed No malware detection
Endor Labs Missed No malware detection
← ctx package (PyPI) XZ Utils backdoor (CVE-2024-3094) →