Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zztestno44 (RubyGems)

Malicious code was discovered in the zztestno44 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; appears to be a test/demonstration package
Ecosystems
Attack vectors
Affected entities
  • zztestno44RubyGems package

The zztestno44 package on RubyGems was found to contain malicious code. The vulnerability was identified and credited to the OpenSSF's malicious packages tracking project, which maintains a public catalog of known malicious software supply chain incidents.\n\nThe package was assigned the identifier MAL-2026-9985 in the OpenSSF malicious packages database. The incident was disclosed on July 18, 2026, via a GitHub Security Advisory (GHSA-973q-jr2q-hvfp).\n\nGiven the naming convention ("zztestno44"), this may be a test or demonstration package used for security research or validation purposes, though the malicious code classification indicates it contained genuine malicious payload.

Indicators of compromise

Packages
  • zztestno44

Remediation

  • Remove or uninstall the zztestno44 package from any systems where it was installed
  • Review application dependencies to ensure zztestno44 is not required
  • Check for any suspicious activity or artifacts left by the package on affected systems
  • Update dependency management tools to block or flag this package

Sources

  1. GitHub Advisory GHSA-973q-jr2q-hvfp · GitHub Advisory Database

Cite this entry

"Malicious code in zztestno44 (RubyGems)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 18, 2026; last updated July 18, 2026. https://supplychainattack.org/incident/malicious-code-in-zztestno44-rubygems-70bu1g

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

    Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.

    RubyGemsCompromised packageMalicious maintainer
  2. resolvedcritical

    Malicious code in zwxbcsacre (RubyGems)

    Malicious code was discovered in the zwxbcsacre RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned identifier MAL-2026-9931.

    RubyGemsCompromised package
  3. resolvedcritical

    Malicious code in zztest17785553774 (RubyGems)

    Malicious code was published in the zztest17785553774 package on RubyGems. The package was identified and reported by the OpenSSF malicious-packages project.

    RubyGemsCompromised package
  4. resolvedcritical

    Malicious code in zztest17785553733 (RubyGems)

    Malicious code was discovered in the RubyGems package zztest17785553733. The package was identified and documented by the OpenSSF malicious packages project.

    RubyGemsCompromised package