Cryptojacking Campaign Exploits RubyGems with 136 Malicious Packages
Article Content
- •136 malicious RubyGems packages have been identified, deploying XMRig miners.
- •The attack spreads through SSH, affecting developer machines and slowing down operations.
- •Researchers documented the campaign on July 22, 2026, highlighting systemic vulnerabilities.
A supply chain attack has compromised RubyGems with 136 malicious packages that deploy an XMRig Monero miner. This attack leverages SSH to propagate itself, affecting developer machines and consuming their computing resources. Researchers documented the campaign on July 22, 2026, revealing systemic vulnerabilities in the Ruby ecosystem. The malicious packages can significantly slow down development work while generating cryptocurrency for the attackers. The incident highlights the need for enhanced security measures in software package management systems. Developers using RubyGems are at risk of having their machines hijacked for cryptomining, leading to potential financial losses and productivity issues. The attack emphasizes the importance of vigilance in reviewing package dependencies and the security of development environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track XMRig in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
BengalSEO Campaign Delivers Malware via SEO Poisoning In March 2026, a significant SEO poisoning campaign named BengalSEO was identified, attributed to two IT service providers in Rajasthan, India. This operation has been active since at least 2015, utilizing Black Hat SEO techniques to create lure pages that redirect users to tech support scams and malware deployment.…