Fun

Two Rubygems Infected With Crypto-Stealing Feature Malware Spotted by Researchers

News Feed - 2020-12-19 06:12:08

Two Rubygems Infected With Crypto-Stealing Feature Malware Spotted by Researchers


New infected Rubygems packages have been spotted in its open-source software repository and which contained malicious code mainly used to steal cryptocurrencies from users via supply chain attack. Two Cryptocurrency-Stealers Rubygems Detected by Researchers at Sonatype


According to Ax Sharma, a security researcher at Sonatype, the two gems detected — pretty_color and ruby-bitcoin — had malware that deployed the attack on Windows machines and replaced any bitcoin (BTC), ethereum (ETH), or monero (XMR) wallet addresses found on the victim’s clipboard by the attackers’ ones.


Rubygems is a package manager for the Ruby programming language that allows developers to integrate code developed by other people. Anyone can upload a “gem” to the repository, open in some way the doors for threat actors to upload their malicious packages.


The researcher explained further about how the attack operates: This means if a user who had mistakenly installed either of these gems was to copy-paste a bitcoin recipient wallet address somewhere on their system, the address would be replaced with that of the attacker, who’d now receive the bitcoins.


During an analysis conducted by the Sonatype Security Research team, it was detected that unless the victim double-checks the wallet address after they paste it, the clipboard hijacker deployed during the supply chain attack will quietly change the address by creating separate malicious scripts contained in VBS files.


Supply Chain Attacks: A Growing Concern


Sharma also warned on the growing trend that supply chain attacks have so far in 2020, considering it a “bigger concern.”


According to Sonatype’s 2020 State of the Software Supply Chain report, there was a 430% increase in upstream software supply chain attacks over the past year, making it “virtually impossible” to chase and keep track of such components manually.


Sonatype’s Sharma adds: Of all activities a ransomware group may conduct on a compromised system, replacing bitcoin wallet address on the clipboard feels more akin to a trivial mischief by an amateur threat actor than to a sophisticated ransomware operation. However, this coincidence does raise a bigger concern, considering how rampant software supply chain attacks have been in 2020.


Will we see a leading role in crypto-related supply chain attacks in 2021? Let us know in the comments section below. Nicehash Crypto Mining Pool "Fully" Reimburses All Users Affected by 2017 Hack SECURITY | 4 hours ago FBI Warns Ransomware Gangs Are Harassing Victims via Telephone Calls to Pay Crypto Ransoms SECURITY | 18 hours ago Tags in this story crypto wallet, Cryptocurrency Security, cryptocurrency wallet, cybersecurity, hijack, Protection, Security, security analysis, security breach, Supply Chain, wallet address


Image Credits: Shutterstock, Pixabay, Wiki Commons Purchase Bitcoin without visiting a cryptocurrency exchange. Buy BTC and BCH here. Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Bitcoin, Ethereum Technical Analysis: BTC Fall Towards $27,000 to Start the Weekend
Bitcoin, Ethereum Technical Analysis: BTC Fall Towards $27,000 to Start the Weekend Bitcoin moved close to a breakout below $27,000 on Saturday, as markets moved lower following a
OpenAI’s GPT-4 Turbo receives stealth update for 2023
Savannah Fortis14 hours agoOpenAI’s GPT-4 Turbo receives stealth update for 2023OpenAI’s most advanced commercial AI model, GTP-4 Turbo, has been quietly updated to a data training set as recently as December 2023 wi
Bitcoin price loses $60K, but a maturing Wyckoff signal gives hope
Yashu Gola8 hours agoBitcoin price loses $60K, but a maturing Wyckoff signal gives hopeThe bullish outlook appears despite the ongoing Bitcoin sell-off, which is being led by the growing risks of a recession in the Unite
‘Sleeping Bitcoin’ Spends Slow Down Considerably in 2022, as 92 Decade-Old BTC Worth $1.79 Million Wake Up
"Sleeping Bitcoin" Spends Slow Down Considerably in 2022, as 92 Decade-Old BTC Worth $1.79 Million Wake Up While the price of bitcoin has remained range bound and coasting along ju
Amaka Nwaokocha14 hours agoSEC vs. Coinbase: New lawyer Patrick Kennedy joins fightLawyer Patrick Kennedy files a motion to appear pro hac vice in the Coinbase vs. U.S. SEC lawsuit for the Chamber of Digital Commerce.235
AI researchers want to solve bot problem by requiring ID to use internet
Tristan Greene4 hours agoAI researchers want to solve bot problem by requiring ID to use internetThe researchers based their ideas on “proof of personhood” technologies developed by the blockchain community.1101 Tota
Mirandus: Open World MMORPG Finally in Web3
Mirandus: Open World MMORPG Finally in Web3 press release PRESS RELEASE.Finally, the moment has arrived. A dozen hours have gone into farming the materials needed for a brand-new mi
Investment Fund Focused on Crypto Mining to Be Created in Russia
Investment Fund Focused on Crypto Mining to Be Created in Russia The establishment of Russia’s first mutual investment fund dedicated to financing cryptocurrency mining operation
David Attlee46 minutes agoMistake or money laundering? User pays $1.6 million for CrypToadz NFTThe purchase was funded from a digital wallet, which has been a part of the chain of transactions, anonymized by the Ethereum
Rachel Wolfson10 hours agoBlockchain companies are creating AI chatbots to help developersBlockchain companies are building AI chatbots to help developers, yet challenges may hamper adoption.637 Total views4 Total shares
Darknet Giant White House Market Drops Bitcoin, Supports Monero Payments Only
Darknet Giant White House Market Drops Bitcoin, Supports Monero Payments Only The prominent darknet marketplace, White House Market, has dropped bitcoin payments
FBI Says Crypto Investment Fraud Rose 183% to $2.57 Billion in 2022
FBI Says Crypto Investment Fraud Rose 183% to $2.57 Billion in 2022 The Federal Bureau of Investigation (FBI) says cryptocurrency investment fraud rose 183% from $907 million in 20