gem-wrappers backdoor reached RubyGems.org
During a platform-level compromise of RubyGems.org (exploiting server vulnerabilities), attackers gained root filesystem access and replaced the legitimate 'gem-wrappers' gem file (v1.1.0) with a malicious version.
Story
gem-wrappers was the package-level artifact exposed by the 2013 RubyGems.org compromise. The attack was not a maintainer deciding to publish hostile code; it was a failure at the hosting platform that distributed gems to the Ruby ecosystem.
Public reporting tied the intrusion to a RubyGems.org server vulnerability that let attacker-controlled gem metadata execute on the service. Once the platform was compromised, the legitimate gem-wrappers 1.1.0 gem file was replaced with a malicious archive.
That made the trust path simple and dangerous. Users asking RubyGems.org for gem-wrappers 1.1.0 could receive the poisoned package from the canonical registry. The source repository was less important than the archive served by the package host.
RubyGems.org took the service offline, audited gems, and restored trust in the distribution platform. This record keeps the package artifact separate from the platform incident because the affected gem version and archive hash are concrete.
Affected Artifacts
gem-wrappers
- Observed
- 2013-01-29 to 2013-02-01
- Compromised Versions
-
- 1.1.0
- Fixed
- Not listed
- Hashes
-
- sha256:fbcf2be93426cbf4f1b2f03b7ac3a8fc85eedd6a8dd42b2f6355c388fed8e00e
- Evidence
- distribution: rubygems.org/gems/gem-wrappers/versions/1.1.0, distribution: rubygems.org/downloads/gem-wrappers-1.1.0.gem, mirror: arstechnica.com/information-technology/2013/02/rubygems-org-hacked-popular-gem-backdoored-with-remote-code-exploit, mirror: nakedsecurity.sophos.com/2013/02/01/rubygems-hacked-gem-wrappers
Incident Context
- Motive
- Unauthorized Access Control
- Attribution
- Person
- Cause
- Compromised Infrastructure
- Transitive
- No
- Actor
- Individual Hacker
External References
- RubyGems.org hacked, popular gem backdoored with remote code exploitarstechnica.com
- RubyGems hacked, gem-wrappers backdoorednakedsecurity.sophos.com
- RubyGems.org hacked, interrupting Heroku services and putting Rails sites at riskventurebeat.com
Source record: oss/attacks/gem-wrappers/meta.yaml