Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zwtd101 (RubyGems)

Malicious code was discovered in the zwtd101 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned advisory GHSA-3fwr-j6xp-prv4.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users of the zwtd101 RubyGems package
Ecosystems
Attack vectors
Affected entities
  • zwtd101RubyGems package

The zwtd101 package on RubyGems was found to contain malicious code. This incident was identified and documented by the OpenSSF's malicious-packages project, which maintains a catalog of known malicious software supply chain incidents.\n\nThe package was assigned GitHub Security Advisory GHSA-3fwr-j6xp-prv4 and classified as critical severity. The malicious package was published on RubyGems and could affect any Ruby developer who installed or depended on this package.\n\nThe incident was disclosed on July 18, 2026, and has been cataloged in the OpenSSF's malicious-packages repository for reference and prevention of future similar incidents.

Indicators of compromise

Packages
  • zwtd101

Remediation

  • Remove the zwtd101 package from all environments
  • Audit systems that may have installed or executed code from zwtd101
  • Review application dependencies to ensure no reliance on zwtd101
  • Update to a safe alternative package if zwtd101 was providing legitimate functionality
  • Monitor for any indicators of compromise from systems that may have used this package

Sources

  1. GitHub Advisory GHSA-3fwr-j6xp-prv4 · GitHub Advisory Database

Cite this entry

"Malicious code in zwtd101 (RubyGems)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 18, 2026; last updated July 18, 2026. https://supplychainattack.org/incident/malicious-code-in-zwtd101-rubygems-nhwb4h

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

    Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.

    RubyGemsCompromised packageMalicious maintainer
  2. resolvedcritical

    Malicious code in zwxbcsacre (RubyGems)

    Malicious code was discovered in the zwxbcsacre RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned identifier MAL-2026-9931.

    RubyGemsCompromised package
  3. resolvedcritical

    Malicious code in zztest17785553774 (RubyGems)

    Malicious code was published in the zztest17785553774 package on RubyGems. The package was identified and reported by the OpenSSF malicious-packages project.

    RubyGemsCompromised package
  4. resolvedcritical

    Malicious code in zztest17785553733 (RubyGems)

    Malicious code was discovered in the RubyGems package zztest17785553733. The package was identified and documented by the OpenSSF malicious packages project.

    RubyGemsCompromised package