Launch Week Day 1: Announcing Security Design Review
CRITICAL RubyGems Malware

Malicious code in newrubylogger (RubyGems)

MAL-2026-1002

Published ยท Modified

Description


__

Source: ossf-package-analysis (d10fd2e8adb621ac6bb3b4cd31357213d90dd17f27cd1f01d5e8e7138686d7c2)

The OpenSSF Package Analysis project identified 'newrubylogger' @ 99.9.1 (rubygems) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Ready to move

Start Securing

Free, no credit card | First findings in minutes