Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zwxbccalag (RubyGems)

Malicious code was discovered in the zwxbccalag RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of zwxbccalag package
Ecosystems
Attack vectors
Affected entities
  • zwxbccalagRubyGems package

The zwxbccalag package on RubyGems was found to contain malicious code. The discovery was credited to the OpenSSF (Open Source Security Foundation) malicious packages project, which maintains a catalog of known malicious packages across multiple ecosystems.\n\nThe incident was documented in GitHub Advisory GHSA-2c29-mw93-gp3q and tracked in the OpenSSF malicious packages repository under identifier MAL-2026-9927.\n\nThis represents a compromised package incident where malicious code was introduced into a RubyGems package, potentially affecting any systems or applications that installed or used this package.

Indicators of compromise

Packages
  • zwxbccalag

Remediation

  • Remove the zwxbccalag package from all affected systems and applications
  • Audit systems that may have installed zwxbccalag for signs of compromise
  • Review application dependencies to identify and replace any reliance on zwxbccalag with legitimate alternatives
  • Monitor for any suspicious activity on systems that previously had this package installed

Sources

  1. GitHub Advisory GHSA-2c29-mw93-gp3q · GitHub Advisory Database

Cite this entry

"Malicious code in zwxbccalag (RubyGems)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 18, 2026; last updated July 18, 2026. https://supplychainattack.org/incident/malicious-code-in-zwxbccalag-rubygems-88k71e

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

    Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.

    RubyGemsCompromised packageMalicious maintainer
  2. resolvedcritical

    Malicious code in zztxtwtmp07 (RubyGems)

    Malicious code was discovered in the zztxtwtmp07 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  3. resolvedcritical

    Malicious code in zzwmgweb02 (RubyGems)

    Malicious code was discovered in the zzwmgweb02 RubyGems package. The package was identified by the OpenSSF malicious-packages project and cataloged as MAL-2026-10004.

    RubyGemsCompromised package
  4. resolvedcritical

    Malicious code in zztestno44 (RubyGems)

    Malicious code was discovered in the zztestno44 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package