{"id":"MAL-2026-3632","summary":"Malicious code in knot-devise-jwt-helper (RubyGems)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ghsa-malware (276381bb1ca0d7664992da8130d70f44c77debd2752b76bf42f2836d96217228)\n## Source: google-open-source-security (a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e)\nThis package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters.\nThe packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.\n\n---\n\nCredit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9fbb5fba02ba2f02395d3d2d43c31b2c482b7a9d/osv/malicious/rubygems/knot-devise-jwt-helper/MAL-2026-3632.json))\n\n## Source: google-open-source-security (a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e)\nThis package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters.\nThe packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.\n","aliases":["GHSA-5mm5-vm3m-435p"],"modified":"2026-07-18T11:04:23.812685767Z","published":"2026-05-13T03:09:00Z","database_specific":{"iocs":{"urls":["https://webhook.site/49c21843-c27c-4a1b-b1f6-037c3998055f"]},"malicious-packages-origins":[{"modified_time":"2026-05-13T03:51:44Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"versions":["1.0.7"],"source":"google-open-source-security","sha256":"a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e","import_time":"2026-05-13T03:53:19.895958Z"},{"modified_time":"2026-07-18T01:57:26Z","versions":["1.0.7"],"source":"ghsa-malware","sha256":"276381bb1ca0d7664992da8130d70f44c77debd2752b76bf42f2836d96217228","import_time":"2026-07-18T10:46:29.098488396Z","id":"GHSA-5mm5-vm3m-435p"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/malicious-ruby-gems-and-go-modules-steal-secrets-poison-ci"},{"type":"WEB","url":"https://socket.dev/blog/malicious-ruby-gems-and-go-modules-steal-secrets-poison-ci"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5mm5-vm3m-435p"}],"affected":[{"package":{"name":"knot-devise-jwt-helper","ecosystem":"RubyGems","purl":"pkg:gem/knot-devise-jwt-helper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.7"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/knot-devise-jwt-helper/MAL-2026-3632.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5"}