Malicious code in zwxbccalag (RubyGems)
Malicious code was discovered in the zwxbccalag RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of zwxbccalag package
- Ecosystems
- Attack vectors
- Affected entities
- zwxbccalagRubyGems package
The zwxbccalag package on RubyGems was found to contain malicious code. The discovery was credited to the OpenSSF (Open Source Security Foundation) malicious packages project, which maintains a catalog of known malicious packages across multiple ecosystems.\n\nThe incident was documented in GitHub Advisory GHSA-2c29-mw93-gp3q and tracked in the OpenSSF malicious packages repository under identifier MAL-2026-9927.\n\nThis represents a compromised package incident where malicious code was introduced into a RubyGems package, potentially affecting any systems or applications that installed or used this package.
Indicators of compromise
- Packages
- zwxbccalag
Remediation
- Remove the zwxbccalag package from all affected systems and applications
- Audit systems that may have installed zwxbccalag for signs of compromise
- Review application dependencies to identify and replace any reliance on zwxbccalag with legitimate alternatives
- Monitor for any suspicious activity on systems that previously had this package installed
Sources
- GitHub Advisory GHSA-2c29-mw93-gp3q · GitHub Advisory Database
Cite this entry
"Malicious code in zwxbccalag (RubyGems)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 18, 2026; last updated July 18, 2026. https://supplychainattack.org/incident/malicious-code-in-zwxbccalag-rubygems-88k71e
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor
Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.
RubyGemsCompromised packageMalicious maintainer - resolvedcritical
Malicious code in zztxtwtmp07 (RubyGems)
Malicious code was discovered in the zztxtwtmp07 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzwmgweb02 (RubyGems)
Malicious code was discovered in the zzwmgweb02 RubyGems package. The package was identified by the OpenSSF malicious-packages project and cataloged as MAL-2026-10004.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztestno44 (RubyGems)
Malicious code was discovered in the zztestno44 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package