Malware & Info-Stealers 2019-2025 Incident #43 CVE-2019-13589

RubyGems mass typosquatting

Estimated Financial Impact
600%+ increase 2020-2021
Blast Radius
Fastlane impersonators; South Korean targeting

What Happened

Multiple campaigns targeted the RubyGems ecosystem including Fastlane plugin impersonators, 60+ malicious gems targeting South Korean marketers, and a ddtracer primed repository attack. Supply chain attacks in RubyGems increased 600%+ between 2020 and 2021.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWARE

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Sonatype (Nexus) Partial Limited ecosystem coverage for this attack
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← getcookies backdoor chain Shai-Hulud npm worm →