{"id":78968,"date":"2020-04-23T13:42:01","date_gmt":"2020-04-23T11:42:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-rubygems-vyyavleno-724-vredonosnyh-paketa"},"modified":"2020-04-23T13:42:01","modified_gmt":"2020-04-23T11:42:01","slug":"v-rubygems-vyyavleno-724-vredonosnyh-paketa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa","title":{"rendered":"Se han detectado 724 paquetes maliciosos en RubyGems","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>La empresa ReversingLabs <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.reversinglabs.com\/blog\/mining-for-malicious-ruby-gems\">ha publicado<\/a><\/noindex> resultados del an\u00e1lisis de uso  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=44576\">type squatting<\/a><\/noindex> en el repositorio de RubyGems. Normalmente, el type squatting se utiliza para distribuir paquetes maliciosos, esperando que un desarrollador descuidado cometa un error tipogr\u00e1fico o no note la diferencia. En el estudio, se identificaron m\u00e1s de 700 paquetes cuyos nombres son similares a paquetes populares y difieren solo en detalles menores, como el uso de letras similares o el uso de guiones bajos en lugar de guiones. <\/p>\n<p>En m\u00e1s de 400 paquetes se encontraron componentes sospechosos de llevar a cabo acciones maliciosas. En particular, hab\u00eda un archivo aaa.png que inclu\u00eda c\u00f3digo ejecutable en formato PE. Estos paquetes estaban vinculados a dos cuentas a trav\u00e9s de las cuales, del 16 al 25 de febrero de 2020, se publicaron <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.reversinglabs.com\/hubfs\/Blog\/ruby_malicious_gems.txt\">724 paquetes maliciosos<\/a><\/noindex>, que en total fueron descargados aproximadamente 95 mil veces. Los investigadores informaron a la administraci\u00f3n de RubyGems y los paquetes maliciosos identificados ya han sido eliminados del repositorio. <\/p>\n<p>Entre los paquetes problem\u00e1ticos identificados, el m\u00e1s popular result\u00f3 ser\u00a0&#171;atlas-client&#187;, que a primera vista es pr\u00e1cticamente indistinguible del paquete leg\u00edtimo\u00a0&#171;<noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/atlas_client\">atlas_client<\/a><\/noindex>&#171;. El paquete mencionado fue descargado 2100 veces (mientras que el paquete normal fue descargado 6496 veces, es decir, los usuarios cometieron errores en casi el 25% de los casos). Los dem\u00e1s paquetes se descargaron en promedio entre 100 y 150 veces y se camuflaron como otros paquetes utilizando una t\u00e9cnica similar de reemplazo de guiones bajos y guiones (por ejemplo, entre <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.reversinglabs.com\/hubfs\/Blog\/ruby_malicious_gems.txt\">los paquetes maliciosos<\/a><\/noindex>: appium-lib, action-mailer_cache_delivery, activemodel_validators, asciidoctor_bibliography, assets-pipeline, apress_validators, ar_octopus-replication-tracking, aliyun-open_search, aliyun-mns, ab_split, apns-polite).<\/p>\n<p>Los paquetes maliciosos inclu\u00edan un archivo PNG en el que, en lugar de la imagen, hab\u00eda un archivo ejecutable para plataformas Windows. El archivo se gener\u00f3 usando la herramienta Ocra Ruby2Exe e inclu\u00eda un archivo autoextra\u00edble con un script Ruby y un int\u00e9rprete Ruby. Al instalar el paquete, el archivo PNG se renombraba a EXE y se ejecutaba. Durante la ejecuci\u00f3n, se creaba y a\u00f1ad\u00eda a la autoejecuci\u00f3n un archivo VBScript. El VBScript malicioso mencionado analizaba en un ciclo el contenido del portapapeles en busca de informaci\u00f3n que recordara direcciones de criptobolsillos y, en caso de detectar alguna, sustitu\u00eda el n\u00famero de la billetera, esperando que el usuario no notara la diferencia y transfiriera fondos a la billetera equivocada. <\/p>\n<p>La investigaci\u00f3n llevada a cabo mostr\u00f3 que no es dif\u00edcil lograr la inclusi\u00f3n de paquetes maliciosos en uno de los repositorios m\u00e1s populares, y estos paquetes pueden permanecer desapercibidos, a pesar de un n\u00famero considerable de descargas. Cabe se\u00f1alar que el problema <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50462\">no<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51056\">espec\u00edfico<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51321\">para<\/a><\/noindex> de RubyGems tambi\u00e9n afecta a otros repositorios populares. Por ejemplo, el a\u00f1o pasado los mismos investigadores <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51336\">detectaron<\/a><\/noindex> en el repositorio NPM un paquete malicioso llamado bb-builder, que utiliza una t\u00e9cnica similar para ejecutar un archivo con el fin de robar contrase\u00f1as. Antes de esto, se hab\u00eda encontrado un backdoor <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49665\">en la dependencia del paquete NPM event-stream, y el c\u00f3digo malicioso se hab\u00eda descargado aproximadamente 8 millones de veces. Los paquetes malignos tambi\u00e9n<\/a><\/noindex> aparecen peri\u00f3dicamente <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49490\">en el repositorio PyPI.<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51975\">La publicaci\u00f3n de la plataforma de JavaScript del servidor Node.js 14.0<\/a><\/noindex> La empresa ReversingLabs public\u00f3 los resultados de un an\u00e1lisis sobre el uso<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52785\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f ReversingLabs \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0442\u0430\u0439\u043f\u0441\u043a\u0432\u043e\u0442\u0442\u0438\u043d\u0433\u0430 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 RubyGems. \u041e\u0431\u044b\u0447\u043d\u043e \u0442\u0430\u0439\u043f\u0441\u043a\u0432\u043e\u0442\u0442\u0438\u043d\u0433 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0440\u0430\u0441\u0441\u0447\u0438\u0442\u0430\u043d\u043d\u044b\u0445 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043d\u0435\u0432\u043d\u0438\u043c\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043f\u0440\u0438 \u043f\u043e\u0438\u0441\u043a\u0435 \u0434\u043e\u043f\u0443\u0441\u0442\u0438\u0442 \u043e\u043f\u0435\u0447\u0430\u0442\u043a\u0443 \u0438\u043b\u0438 \u043d\u0435 \u0437\u0430\u043c\u0435\u0442\u0438\u0442 \u0440\u0430\u0437\u043d\u0438\u0446\u044b. \u0412 \u0445\u043e\u0434\u0435 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f \u0431\u044b\u043b\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 700 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0445\u043e\u0436\u0438 \u0441 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u043c\u0438 \u043f\u0430\u043a\u0435\u0442\u0430\u043c\u0438 \u0438 \u043e\u0442\u043b\u0438\u0447\u0430\u044e\u0442\u0441\u044f \u043d\u0435\u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u043c\u0438 \u0434\u0435\u0442\u0430\u043b\u044f\u043c\u0438, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0437\u0430\u043c\u0435\u043d\u043e\u0439 \u043f\u043e\u0445\u043e\u0436\u0438\u0445 \u0431\u0443\u043a\u0432 \u0438\u043b\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-78968","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f ReversingLabs \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 RubyGems \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 724 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f ReversingLabs \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-23T11:42:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-23T11:42:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Se han identificado 724 paquetes maliciosos en RubyGems | ProHoster","description":"Los resultados del an\u00e1lisis de ReversingLabs muestran","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 RubyGems \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 724 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u0430 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f ReversingLabs \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-23T11:42:01+00:00","article:modified_time":"2020-04-23T11:42:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"78968","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:47:25","updated":"2022-09-28 01:38:04","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/78968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=78968"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/78968\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=78968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=78968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=78968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}