Multiple campaigns targeted the RubyGems ecosystem including Fastlane plugin impersonators, 60+ malicious gems targeting South Korean marketers, and a ddtracer primed repository attack. Supply chain attacks in RubyGems increased 600%+ between 2020 and 2021.
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS |
| Sonatype (Nexus) | Partial | Limited ecosystem coverage for this attack |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |