Fun

Two Rubygems Infected With Crypto-Stealing Feature Malware Spotted by Researchers

News Feed - 2020-12-19 06:12:08

Two Rubygems Infected With Crypto-Stealing Feature Malware Spotted by Researchers


New infected Rubygems packages have been spotted in its open-source software repository and which contained malicious code mainly used to steal cryptocurrencies from users via supply chain attack. Two Cryptocurrency-Stealers Rubygems Detected by Researchers at Sonatype


According to Ax Sharma, a security researcher at Sonatype, the two gems detected — pretty_color and ruby-bitcoin — had malware that deployed the attack on Windows machines and replaced any bitcoin (BTC), ethereum (ETH), or monero (XMR) wallet addresses found on the victim’s clipboard by the attackers’ ones.


Rubygems is a package manager for the Ruby programming language that allows developers to integrate code developed by other people. Anyone can upload a “gem” to the repository, open in some way the doors for threat actors to upload their malicious packages.


The researcher explained further about how the attack operates: This means if a user who had mistakenly installed either of these gems was to copy-paste a bitcoin recipient wallet address somewhere on their system, the address would be replaced with that of the attacker, who’d now receive the bitcoins.


During an analysis conducted by the Sonatype Security Research team, it was detected that unless the victim double-checks the wallet address after they paste it, the clipboard hijacker deployed during the supply chain attack will quietly change the address by creating separate malicious scripts contained in VBS files.


Supply Chain Attacks: A Growing Concern


Sharma also warned on the growing trend that supply chain attacks have so far in 2020, considering it a “bigger concern.”


According to Sonatype’s 2020 State of the Software Supply Chain report, there was a 430% increase in upstream software supply chain attacks over the past year, making it “virtually impossible” to chase and keep track of such components manually.


Sonatype’s Sharma adds: Of all activities a ransomware group may conduct on a compromised system, replacing bitcoin wallet address on the clipboard feels more akin to a trivial mischief by an amateur threat actor than to a sophisticated ransomware operation. However, this coincidence does raise a bigger concern, considering how rampant software supply chain attacks have been in 2020.


Will we see a leading role in crypto-related supply chain attacks in 2021? Let us know in the comments section below. Nicehash Crypto Mining Pool "Fully" Reimburses All Users Affected by 2017 Hack SECURITY | 4 hours ago FBI Warns Ransomware Gangs Are Harassing Victims via Telephone Calls to Pay Crypto Ransoms SECURITY | 18 hours ago Tags in this story crypto wallet, Cryptocurrency Security, cryptocurrency wallet, cybersecurity, hijack, Protection, Security, security analysis, security breach, Supply Chain, wallet address


Image Credits: Shutterstock, Pixabay, Wiki Commons Purchase Bitcoin without visiting a cryptocurrency exchange. Buy BTC and BCH here. Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Iran Adopts Bitcoin for International Trade Amid Heavy Sanctions, Falling Rial, Soaring Inflation
Iran Adopts Bitcoin for International Trade Amid Heavy Sanctions, Falling Rial, Soaring Inflation The Iranian government has adopted bitcoin for international tr
Terraform Labs was ‘built on lies’ — SEC at trial
Turner Wright5 hours agoTerraform Labs was ‘built on lies’ — SEC at trialThe civil trial between the U.S. Securities and Exchange Commission and Terraform Labs entered its tenth day without the attendance of Do Kwo
North American Bitcoin ETF’s First Trading Day Captures $165M in Volume
North American Bitcoin ETF"s First Trading Day Captures $165M in Volume The North American Purpose Bitcoin ETF launch on Thursday saw massive demand, as more tha
US Bitcoin ETFs see record $17B in net inflows
Amaka Nwaokocha12 hours agoUS Bitcoin ETFs see record $17B in net inflowsThe consistent inflows into Bitcoin spot ETFs signal a robust and growing demand for regulated Bitcoin investment vehicles.11057 Total views4 Total
Arijit Sarkar14 hours ago5 nations challenge crypto experts and investigators to target tax crimesThe J5 generates significant leads through events, which, in the past, has helped uncover multimillion-dollar crypto Ponzi
Philippines SEC orders Apple and Google to remove Binance from app stores
Savannah Fortis13 hours agoPhilippines SEC orders Apple and Google to remove Binance from app storesThe Philippines SEC mandates the removal of the Binance app from Google and Apple stores in the country citing security
Dionne Warwick to Headline DOGE-Themed Festival Dogepalooza 2021
Dionne Warwick to Headline DOGE-Themed Festival Dogepalooza 2021 While dogecoin fans saw the first crypto-scented Dogecan body spray made by Axe, Oscar Mayer&rsq
Bank of England’s Cunliffe: Crypto Threat to Financial Stability ‘Getting Closer’ — Urges Regulators to Act Now
Bank of England"s Cunliffe: Crypto Threat to Financial Stability "Getting Closer" — Urges Regulators to Act Now Bank of England’s deputy governor for financial stability,
Marcel Pechman5 hours ago3 reasons why Bitcoin is struggling to rally above $28.5KBitcoin started the week with an uptick in investor sentiment, but there are three major factors preventing BTC price from recapturing the
Virtual Currency-Based Sale Agreement an Invalid Contract, Chinese Court Rules
Virtual Currency-Based Sale Agreement an Invalid Contract, Chinese Court Rules A virtual currency cannot be circulated in the market as a currency, therefore a vehicle sale contrac
David Attlee3 hours agoUS regulators continue to discuss crypto: Law Decoded, Nov. 13–20Elizabeth Warren continues pressing for tighter regulation, and Vivek Ramaswamy promises to defend crypto from the government’s
Fintechs Accounted for Over 30% of Tracked Kenyan Tech Startups in 2022 — Study
Fintechs Accounted for Over 30% of Tracked Kenyan Tech Startups in 2022 — Study As of November 2022, Kenyan fintechs accounted for 30.2% or 93 out of the 308 tracked tech startup