{"id":"MAL-2026-3634","summary":"Malicious code in knot-rails-assets-pipeline (RubyGems)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: google-open-source-security (a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e)\nThis package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters.\nThe packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.\n","aliases":["GHSA-5548-89gq-w58f"],"modified":"2026-07-23T07:55:09.895997789Z","published":"2026-05-13T03:09:00Z","database_specific":{"iocs":{"urls":["https://webhook.site/49c21843-c27c-4a1b-b1f6-037c3998055f"]},"malicious-packages-origins":[{"versions":["6.1.11"],"import_time":"2026-05-13T03:53:19.895958Z","modified_time":"2026-05-13T03:51:44Z","ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"sha256":"a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e","source":"google-open-source-security"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/malicious-ruby-gems-and-go-modules-steal-secrets-poison-ci"}],"affected":[{"package":{"name":"knot-rails-assets-pipeline","ecosystem":"RubyGems","purl":"pkg:gem/knot-rails-assets-pipeline"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.1.11"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/knot-rails-assets-pipeline/MAL-2026-3634.json"}}],"schema_version":"1.7.5"}