Account Takeover 2019 Incident #5 CVE-2019-15224

rest-client gem

Estimated Financial Impact
$1-5M
Blast Radius
113M total downloads; Rails production apps

What Happened

Attacker compromised maintainer Matthew Manning's RubyGems account via credential stuffing and published malicious versions containing a backdoor that activated in Rails production environments, fetched remote code from Pastebin, and exfiltrated credentials. The gem had 113M total downloads; malicious versions were downloaded ~1,000 times.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects source-registry divergence

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_STALE_RELEASESOURCE_MALFORMED_METADATA

How Every Tool Performed

2 Caught 0 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects source-registry divergence
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Sonatype (Nexus) Missed Limited ecosystem coverage for this attack
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← coa and rc packages bootstrap-sass gem →