Launch Week Day 1: Announcing Security Design Review
CRITICAL RubyGems Malware

Malicious code in knot-simple-formatter (RubyGems)

MAL-2026-3636

Published ยท Modified

Description


__

Source: google-open-source-security (a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e)

This package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters.
The packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.

Ready to move

Start Securing

Free, no credit card | First findings in minutes