active-support impersonates 'activesupport' gem
Critical severity
GitHub Reviewed
Published
Aug 13, 2018
to the GitHub Advisory Database
•
Updated Jan 18, 2023
Description
Published to the GitHub Advisory Database
Aug 13, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 18, 2023
The
active-support
ruby gem gem is malware and duplicates the officialactivesupport
(no hyphen) gem, but adds a compiled extension. The extension attempts to resolve a base64 encoded domain (29faea63.planfhntage.de), downloads a payload, and executes.This trojan horse gem could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system. No version of this gem should be considered safe.
References