Malicious Libraries Uploaded to RubyGems Repository

Tya Hariharan's Avatar

Tya Hariharan

21 Apr, 2020 10:47 PM

Hi,

We just heard that malicious libraries were uploaded to RubyGems. My question here is, how can we find out which libraries are malicious or whether we have installed them? Do you plan on publishing a list?

Thanks,
Tya

  1. Support Staff 1 Posted by sonalkr132 on 25 Apr, 2020 09:10 PM

    sonalkr132's Avatar

    Hi Tya,

    We maintain a wiki for most of them gems we removed for security reasons, you can find it here: https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accou...

    whether we have installed them?

    Note that your host could have only installed the gem if you or any of the libraries you used made a typo matching the above mentioned list.

Reply to this discussion

Internal reply

Formatting help / Preview (switch to plain text) No formatting (switch to Markdown)

Attaching KB article:

»

Attached Files

You can attach files up to 10MB

If you don't have an account yet, we need to confirm you're human and not a machine trying to post spam.

Keyboard shortcuts

Generic

? Show this help
ESC Blurs the current field

Comment Form

r Focus the comment reply box
^ + ↩ Submit the comment

You can use Command ⌘ instead of Control ^ on Mac