{"id":37310,"date":"2019-10-31T22:16:54","date_gmt":"2019-10-31T19:16:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\/"},"modified":"2019-10-31T22:16:54","modified_gmt":"2019-10-31T19:16:54","slug":"v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","title":{"rendered":"Malicious code detected in rest-client and 10 other Ruby packages","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In the popular gem package <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/rest-client\">rest-client<\/a><\/noindex>, which has a total of 113 million downloads, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rest-client\/rest-client\/issues\/713\">identified<\/a><\/noindex> malicious code injection (CVE-2019-15224), which downloads executable commands and sends information to an external host. The attack occurred through <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rest-client\/rest-client\/issues\/713#issuecomment-522735093\">compromise<\/a><\/noindex> of the developer account of rest-client in the rubygems.org repository, after which attackers published versions 1.6.10-1.6.13 on August 13 and 14, with malicious changes included. About a thousand users managed to download the malicious versions before they were blocked (the attackers released updates for older versions to avoid drawing attention).<\/p>\n<p>Malicious modification overrides the method &#171;#authenticate&#187; in the class<br \/>\nIdentity, resulting in each call to the method causing the email and password provided during the authentication attempt to be sent to the attackers' host. This allows interception of user login parameters for services using the Identity class that have installed a vulnerable version of the rest-client library, which <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/rest-client\/reverse_dependencies\">is listed<\/a><\/noindex> as a dependency in many popular Ruby packages, including ast (64 million downloads), oauth (32 million), fastlane (18 million), and kubeclient (3.7 million).<\/p>\n<p>Additionally, a backdoor was added to the code allowing arbitrary Ruby code to be executed via the eval function. The code is transmitted via a cookie signed with the attacker's key. To inform the attackers about the installation of the malicious package on an external host, the URL of the victim's system and a set of environment details, such as saved database and cloud service passwords, are sent. Attempts to upload cryptocurrency mining scripts have been recorded using the aforementioned malicious code.<\/p>\n<p>After examining the malicious code, it was found that similar changes are also present in <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rubygems\/rubygems.org\/issues\/2097\">seven vulnerabilities have been identified<\/a><\/noindex>10 packages <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rubygems\/rubygems.org\/wiki\/Gems-yanked-and-accounts-locked#19-aug-2019\">in Ruby Gems, which were not captured but were specifically prepared by the attackers based on other popular libraries with similar names, where the hyphen was replaced with an underscore or vice versa (for example, based on<\/a><\/noindex> cron-parser <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/cron-parser\">, a malicious package named cron_parser was created, and based on<\/a><\/noindex> doge_coin <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/doge_coin\">, a malicious package named doge-coin was created). Problematic packages include:<\/a><\/noindex> coin_base<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/coin_base\">blockchain_wallet<\/a><\/noindex>: 4.2.2, 4.2.1\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/blockchain_wallet\">awesome-bot<\/a><\/noindex>: 0.0.6, 0.0.7\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/awesome-bot\">doge-coin<\/a><\/noindex>: 1.18.0\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/doge-coin\">capistrano-colors<\/a><\/noindex>: 1.0.2\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/capistrano-colors\">bitcoin_vanity<\/a><\/noindex>: 0.5.5\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/bitcoin_vanity\">lita_coin<\/a><\/noindex>: 4.3.3\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/lita_coin\">coming-soon<\/a><\/noindex>: 0.0.3\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/coming-soon\">omniauth_amazon<\/a><\/noindex>: 0.2.8\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/omniauth_amazon\">cron_parser<\/a><\/noindex>: 1.0.1\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/cron_parser\">The first malicious package from this list was posted on May 12, but most appeared in July. In total, the listed packages were downloaded about 2500 times.<\/a><\/noindex>: 1.0.12, 1.0.13, 0.1.4\n<\/ul>\n<p>The first malicious package from this list was uploaded on May 12, but most appeared in July. In total, the specified packages have been downloaded about 2500 times.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51321\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 (CVE-2019-15224), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u0442 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043d\u0430 \u0432\u043d\u0435\u0448\u043d\u0438\u0439 \u0445\u043e\u0441\u0442. \u0410\u0442\u0430\u043a\u0430 \u0431\u044b\u043b\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u0435\u0434\u0435\u043d\u0430 \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u044e \u0443\u0447\u0451\u0442\u043d\u043e\u0439 \u0437\u0430\u043f\u0438\u0441\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 rest-client \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 rubygems.org, \u043f\u043e\u0441\u043b\u0435 \u0447\u0435\u0433\u043e \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 13 \u0438 14 \u0430\u0432\u0433\u0443\u0441\u0442\u0430 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 1.6.10-1.6.13, \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0449\u0438\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f. \u0414\u043e \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u0439 \u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37310","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 rest-client \u0438 \u0435\u0449\u0451 10 Ruby-\u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:16:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:16:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Malicious code found in rest-client and 10 other Ruby packages | ProHoster","description":"In the popular gem package rest-client, which has a total of 113 million downloads,","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 rest-client \u0438 \u0435\u0449\u0451 10 Ruby-\u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 | ProHoster","og:description":"\u0412 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u043c gem-\u043f\u0430\u043a\u0435\u0442\u0435 rest-client, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 113 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a,","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/v-rest-client-i-eshhyo-10-ruby-paketah-vyyavlen-vredonosnyj-kod","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:16:54+00:00","article:modified_time":"2019-10-31T19:16:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37310","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 17:14:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:29:58","updated":"2026-01-23 17:14:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=37310"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37310\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=37310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=37310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=37310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}