THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalrubygems·credential theft·osv

Malicious code in knot-date-utils-rb (RubyGems)

knot-date-utils-rb

Risk score

92

AI summary

Indexed incident for knot-date-utils-rb (rubygems).

Description


-= Per source details. Do not edit below this line.=-

Source: google-open-source-security (a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e)

This package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters.
The packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.

Technical details

Affected versions

<function fixed() { [native code] }

Indicators

  • affected_version<function fixed() { [native code] }75%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents