An attacker compromised a maintainer's RubyGems account and published a malicious version with a stealthy RCE backdoor hidden in lib/active-controller/middleware.rb that intercepted HTTP cookies for arbitrary code execution. The attacker also yanked the legitimate version to force upgrades. bootstrap-sass had 28M total downloads and ~1,670 directly exposed GitHub repos.
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects source-registry divergence
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects source-registry divergence |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Sonatype (Nexus) | Missed | Limited ecosystem coverage for this attack |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |