Malicious code in zztargettest18587 (RubyGems)
Malicious code was discovered in the RubyGems package zztargettest18587. The package was identified and documented by the OpenSSF malicious packages project.
- Disclosed
- Last updated
- Blast radius
- Low (appears to be a test/target package with limited real-world adoption)
- Ecosystems
- Attack vectors
- Affected entities
- zztargettest18587RubyGems package containing malicious code
A RubyGems package named zztargettest18587 was found to contain malicious code. The discovery was credited to the OpenSSF (Open Source Security Foundation) and documented in their malicious packages repository.\n\nThe package was identified with the malicious package identifier MAL-2026-9975 and reported through GitHub's advisory system (GHSA-4wfw-gjrc-9qqv). The package name suggests it may be a test or target package used for security research or testing purposes.\n\nThe incident was published on July 18, 2026, and appears to have been contained through identification and advisory publication."
Indicators of compromise
- Packages
- zztargettest18587
Remediation
- Remove zztargettest18587 from any Ruby projects or dependencies
- Audit project dependencies for any versions of zztargettest18587 that may have been installed
- Review GitHub Security Advisory GHSA-4wfw-gjrc-9qqv for specific details on the malicious behavior
- Consult the OpenSSF malicious packages repository for technical indicators of compromise
Sources
- GitHub Advisory GHSA-4wfw-gjrc-9qqv · GitHub Advisory Database
Cite this entry
"Malicious code in zztargettest18587 (RubyGems)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 18, 2026; last updated July 18, 2026. https://supplychainattack.org/incident/malicious-code-in-zztargettest18587-rubygems-ygf21w
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor
Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.
RubyGemsCompromised packageMalicious maintainer - resolvedcritical
Malicious code in zwxbcsacre (RubyGems)
Malicious code was discovered in the zwxbcsacre RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned identifier MAL-2026-9931.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest17785553774 (RubyGems)
Malicious code was published in the zztest17785553774 package on RubyGems. The package was identified and reported by the OpenSSF malicious-packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest17785553733 (RubyGems)
Malicious code was discovered in the RubyGems package zztest17785553733. The package was identified and documented by the OpenSSF malicious packages project.
RubyGemsCompromised package