Fun

Two Rubygems Infected With Crypto-Stealing Feature Malware Spotted by Researchers

News Feed - 2020-12-19 06:12:08

Two Rubygems Infected With Crypto-Stealing Feature Malware Spotted by Researchers


New infected Rubygems packages have been spotted in its open-source software repository and which contained malicious code mainly used to steal cryptocurrencies from users via supply chain attack. Two Cryptocurrency-Stealers Rubygems Detected by Researchers at Sonatype


According to Ax Sharma, a security researcher at Sonatype, the two gems detected — pretty_color and ruby-bitcoin — had malware that deployed the attack on Windows machines and replaced any bitcoin (BTC), ethereum (ETH), or monero (XMR) wallet addresses found on the victim’s clipboard by the attackers’ ones.


Rubygems is a package manager for the Ruby programming language that allows developers to integrate code developed by other people. Anyone can upload a “gem” to the repository, open in some way the doors for threat actors to upload their malicious packages.


The researcher explained further about how the attack operates: This means if a user who had mistakenly installed either of these gems was to copy-paste a bitcoin recipient wallet address somewhere on their system, the address would be replaced with that of the attacker, who’d now receive the bitcoins.


During an analysis conducted by the Sonatype Security Research team, it was detected that unless the victim double-checks the wallet address after they paste it, the clipboard hijacker deployed during the supply chain attack will quietly change the address by creating separate malicious scripts contained in VBS files.


Supply Chain Attacks: A Growing Concern


Sharma also warned on the growing trend that supply chain attacks have so far in 2020, considering it a “bigger concern.”


According to Sonatype’s 2020 State of the Software Supply Chain report, there was a 430% increase in upstream software supply chain attacks over the past year, making it “virtually impossible” to chase and keep track of such components manually.


Sonatype’s Sharma adds: Of all activities a ransomware group may conduct on a compromised system, replacing bitcoin wallet address on the clipboard feels more akin to a trivial mischief by an amateur threat actor than to a sophisticated ransomware operation. However, this coincidence does raise a bigger concern, considering how rampant software supply chain attacks have been in 2020.


Will we see a leading role in crypto-related supply chain attacks in 2021? Let us know in the comments section below. Nicehash Crypto Mining Pool "Fully" Reimburses All Users Affected by 2017 Hack SECURITY | 4 hours ago FBI Warns Ransomware Gangs Are Harassing Victims via Telephone Calls to Pay Crypto Ransoms SECURITY | 18 hours ago Tags in this story crypto wallet, Cryptocurrency Security, cryptocurrency wallet, cybersecurity, hijack, Protection, Security, security analysis, security breach, Supply Chain, wallet address


Image Credits: Shutterstock, Pixabay, Wiki Commons Purchase Bitcoin without visiting a cryptocurrency exchange. Buy BTC and BCH here. Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Hashrate recovery reduces Bitcoin miners’ selling pressure in July
Ana Paula Pereira6 hours agoHashrate recovery reduces Bitcoin miners’ selling pressure in JulyMiner revenues soar 50%, pushing Bitcoin hashrate higher and reducing selling pressure from miners’ reserves.2002 Total vi
Toncoin price risks correction after TON’s 34% surge in 2 weeks
Yashu Gola7 hours agoToncoin price risks correction after TON’s 34% surge in 2 weeksThe bullish scenario has TON’s price rallying 65% in July if the classic bullish continuation breakout setup plays out.463 Total vie
Kraken-CertiK saga turns murky as part of exploited funds go ‘missing’
Prashant Jha5 hours agoKraken-CertiK saga turns murky as part of exploited funds go ‘missing’Kraken is planning to take legal action against security firm CertiK as the “white hat” operation by the security firm
RFK Jr’s running mate floats ‘unity party’ with former President Trump
Vince Quill2 hours agoRFK Jr’s running mate floats ‘unity party’ with former President TrumpNicole Shanahan claimed that 51% of Americans were against the two-party system dominating modern United States politics.5
Number Of Bitcoin Bulls Increases As Funding Rate Shows Steady Growth – Details
Este artículo también está disponible en español. Bitcoin has rebounded strongly from the $65,000 mark after a 6% dip from Monday’s high of around $69,500. Despite the
Dogecoin Price Looking To Close Weekly Candle Above The Yellow Line, Why $10 Is Possible If This Happens
Este artículo también está disponible en español. A crypto analyst has disclosed that the Dogecoin pricemay be positioning itself for a significant move upward as it appr
Francisco Rodrigues9 hours agoBlockchain devs expect complications from EU smart contract kill switchThe EU’s Data Act could introduce “kill switch” requirements for smart contracts, raising questions about how dec
Bitcoin Under Threat? Analyst Explores Two Bearish Black Swan Scenarios to Watch
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Ideaology’s IEO Ushers the Launch of Blockchain Platform for Innovators
Ideaology"s IEO Ushers the Launch of Blockchain Platform for Innovators PRESS RELEASE. DUBAI, UAE – Ideaology is proud to announce its IDEA token pre-sale
Biggest Movers: QNT Close to 2-Month High Despite Recent Declines, NEAR Moves Toward 1-Year Low
Biggest Movers: QNT Close to 2-Month High Despite Recent Declines, NEAR Moves Toward 1-Year Low QNT was trading close to recent highs on Wednesday, as prices were battling through
DOJ Files First Criminal Complaint Against US Citizen Allegedly Using Cryptocurrency to Evade Sanctions
DOJ Files First Criminal Complaint Against US Citizen Allegedly Using Cryptocurrency to Evade Sanctions The Department of Justice (DOJ) has filed its first criminal complaint again
Digital Wealth Pioneer Yield App Unveils Mobile App for iOS and Android
Digital Wealth Pioneer Yield App Unveils Mobile App for iOS and Android press release PRESS RELEASE.ESTONIA — 17 JUNE 2022 —Yield App, a global FinTech company and dig