Launch Week Day 1: Announcing Security Design Review
CRITICAL RubyGems Malware

Malicious code in rubocop-vintedmetrics (RubyGems)

MAL-2026-996

Published ยท Modified

Description


__

Source: ossf-package-analysis (c8e90dd88f71e05719940997342cf6a367387fc68045f091a864d8f8e7e62be8)

The OpenSSF Package Analysis project identified 'rubocop-vintedmetrics' @ 9.9.12 (rubygems) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Ready to move

Start Securing

Free, no credit card | First findings in minutes