Fun

Two Rubygems Infected With Crypto-Stealing Feature Malware Spotted by Researchers

News Feed - 2020-12-19 06:12:08

Two Rubygems Infected With Crypto-Stealing Feature Malware Spotted by Researchers


New infected Rubygems packages have been spotted in its open-source software repository and which contained malicious code mainly used to steal cryptocurrencies from users via supply chain attack. Two Cryptocurrency-Stealers Rubygems Detected by Researchers at Sonatype


According to Ax Sharma, a security researcher at Sonatype, the two gems detected — pretty_color and ruby-bitcoin — had malware that deployed the attack on Windows machines and replaced any bitcoin (BTC), ethereum (ETH), or monero (XMR) wallet addresses found on the victim’s clipboard by the attackers’ ones.


Rubygems is a package manager for the Ruby programming language that allows developers to integrate code developed by other people. Anyone can upload a “gem” to the repository, open in some way the doors for threat actors to upload their malicious packages.


The researcher explained further about how the attack operates: This means if a user who had mistakenly installed either of these gems was to copy-paste a bitcoin recipient wallet address somewhere on their system, the address would be replaced with that of the attacker, who’d now receive the bitcoins.


During an analysis conducted by the Sonatype Security Research team, it was detected that unless the victim double-checks the wallet address after they paste it, the clipboard hijacker deployed during the supply chain attack will quietly change the address by creating separate malicious scripts contained in VBS files.


Supply Chain Attacks: A Growing Concern


Sharma also warned on the growing trend that supply chain attacks have so far in 2020, considering it a “bigger concern.”


According to Sonatype’s 2020 State of the Software Supply Chain report, there was a 430% increase in upstream software supply chain attacks over the past year, making it “virtually impossible” to chase and keep track of such components manually.


Sonatype’s Sharma adds: Of all activities a ransomware group may conduct on a compromised system, replacing bitcoin wallet address on the clipboard feels more akin to a trivial mischief by an amateur threat actor than to a sophisticated ransomware operation. However, this coincidence does raise a bigger concern, considering how rampant software supply chain attacks have been in 2020.


Will we see a leading role in crypto-related supply chain attacks in 2021? Let us know in the comments section below. Nicehash Crypto Mining Pool "Fully" Reimburses All Users Affected by 2017 Hack SECURITY | 4 hours ago FBI Warns Ransomware Gangs Are Harassing Victims via Telephone Calls to Pay Crypto Ransoms SECURITY | 18 hours ago Tags in this story crypto wallet, Cryptocurrency Security, cryptocurrency wallet, cybersecurity, hijack, Protection, Security, security analysis, security breach, Supply Chain, wallet address


Image Credits: Shutterstock, Pixabay, Wiki Commons Purchase Bitcoin without visiting a cryptocurrency exchange. Buy BTC and BCH here. Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

‘Money-hungry VCs’ are bad for token launches in the long term — Analyst
Zoltan Vardai11 hours ago‘Money-hungry VCs’ are bad for token launches in the long term — AnalystCurrent inflows into altcoins are insufficient to offset some of the big token unlocks and selling pressure from VCs.
Biggest Movers: Tron Climbs to 5-Month High, With WAVES up 15%
Biggest Movers: Tron Climbs to 5-Month High, With WAVES up 15% Tron (TRX) rallied to a five-month high earlier in today’s session, as bulls continued to feed off recent news
South Korea implements tougher rules for crypto exchange listings
Amaka Nwaokocha13 hours agoSouth Korea implements tougher rules for crypto exchange listingsHowever, tokens listed on a licensed exchange for over two years may not need to meet these new criteria.872 Total views6 Total
Speculation runs wild for new GPT model after Altman posts strawberry garden
Ciaran Lyons2 hours agoSpeculation runs wild for new GPT model after Altman posts strawberry gardenOpenAI CEO Sam Altman’s unusual post about his garden has left X wondering if it’s a far-fetched hint about the next
Report: Binance Asked to Provide More Information as Dubai Tightens Screws Against Crypto Entities
Report: Binance Asked to Provide More Information as Dubai Tightens Screws Against Crypto Entities Dubai’s Virtual Assets Regulatory Authority (VARA) has reportedly asked Bin
Did Bitcoin Runes already peak?
Lugui Tillier3 hours agoDid Bitcoin Runes already peak?Tokens on the Runes Protocol are down from their peak, but don"t count them out yet. The protocol is less than three months old — and it"s just getting started.12
MetaMask launches pilot self-custody debit card with Mastercard
Vince Quill7 hours agoMetaMask launches pilot self-custody debit card with MastercardMore than 1 billion individuals remain unbanked or lack adequate access to banking services, according to 2022 data from the World Bank
Bitcoin, Ethereum Technical Analysis: BTC, ETH Consolidate Below Key Resistance Levels
Bitcoin, Ethereum Technical Analysis: BTC, ETH Consolidate Below Key Resistance Levels Following strong gains during Wednesday’s session, bitcoin and ethereum both saw price
Price analysis 5/1: BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA, AVAX, SHIB
Rakesh Upadhyay7 hours agoPrice analysis 5/1: BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA, AVAX, SHIBBitcoin’s drop to $56,500 crushed bullish traders’ sentiment and took a heavy toll on altcoin prices but are generation
Peter Brandt Predicts When Bitcoin Price Might Reach $150,000, Technical Signals Show Where Market Is At
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Derek Andersen10 hours agoItalian central bank backs DeFi tokenization project with Polygon, FireblocksThe Italian central bank’s Milano Hub has selected a project headed by Cetif Advisory and Polygon Labs in its secon
Tom Blackstone9 hours agoBinance’s indecision to freeze BNB wallets drew controversy in this $11M rug pullAs it turns out, Binance does, in fact, have the power to freeze private wallet addresses on BNB Chain — albei