Malicious RubyGems Turn Developer Machines Into Monero Miners and Spread Through SSH
A malicious RubyGems campaign has turned seemingly useful developer packages into tools for hidden cryptocurrency mining. The poisoned packages can consume a machine’s computing power, slow down development work, and quietly generate Monero for the attackers. The campaign also goes beyond a typical package-based infection. One set of malicious gems can examine a compromised developer […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
