Account Takeover 2019 Incident #6 CVE-2019-10842

bootstrap-sass gem

Estimated Financial Impact
$1-5M
Blast Radius
28M total downloads; 1670 repos exposed

What Happened

An attacker compromised a maintainer's RubyGems account and published a malicious version with a stealthy RCE backdoor hidden in lib/active-controller/middleware.rb that intercepted HTTP cookies for arbitrary code execution. The attacker also yanked the legitimate version to force upgrades. bootstrap-sass had 28M total downloads and ~1,670 directly exposed GitHub repos.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects source-registry divergence

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWARESOURCE_MALFORMED_METADATA

How Every Tool Performed

2 Caught 0 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects source-registry divergence
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Sonatype (Nexus) Missed Limited ecosystem coverage for this attack
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← rest-client gem chalk/debug Shai-Hulud phishing →