Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in zztxtwtmp09 (RubyGems)

Malicious code was published in the zztxtwtmp09 RubyGems package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-g2mw-hc98-7xw3.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of the malicious package versions
Ecosystems
Attack vectors
Affected entities
  • zztxtwtmp09

The RubyGems package zztxtwtmp09 contained malicious code and was identified as part of the OpenSSF's malicious-packages tracking effort. The advisory was published on 2026-07-18 and assigned GitHub Advisory identifier GHSA-g2mw-hc98-7xw3.\n\nThe malicious package was detected and cataloged by the OpenSSF malicious-packages project, which maintains a repository of known malicious software supply chain incidents. This incident is tracked under the identifier MAL-2026-9996.\n\nUsers who have installed or depend on zztxtwtmp09 should immediately remove or update to a safe version if one is available, or remove the dependency entirely.

Indicators of compromise

Packages
  • zztxtwtmp09

Remediation

  • Remove the zztxtwtmp09 package from all projects and dependencies
  • Audit systems that may have installed or executed code from zztxtwtmp09
  • Check for any suspicious activity or artifacts left by the malicious package
  • Review the OpenSSF malicious-packages repository for additional context and indicators of compromise

Sources

  1. GitHub Advisory GHSA-g2mw-hc98-7xw3 · GitHub Advisory Database

Cite this entry

"Malicious code in zztxtwtmp09 (RubyGems)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 18, 2026; last updated July 18, 2026. https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp09-rubygems-5nj6fz

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

    Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.

    RubyGemsCompromised packageMalicious maintainer
  2. resolvedcritical

    Malicious code in zwxbcsacre (RubyGems)

    Malicious code was discovered in the zwxbcsacre RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned identifier MAL-2026-9931.

    RubyGemsCompromised package
  3. resolvedcritical

    Malicious code in zztest17785553774 (RubyGems)

    Malicious code was published in the zztest17785553774 package on RubyGems. The package was identified and reported by the OpenSSF malicious-packages project.

    RubyGemsCompromised package
  4. resolvedcritical

    Malicious code in zztest17785553733 (RubyGems)

    Malicious code was discovered in the RubyGems package zztest17785553733. The package was identified and documented by the OpenSSF malicious packages project.

    RubyGemsCompromised package