Close Menu
    What's Hot

    Most popular stories on GeekWire for the week of May 24, 2026 – GeekWire

    Growing US reliance on Chinese biotechs prompts national security fears

    Viking Holdings: At New Highs, And Further To Go (NYSE:VIK)

    Facebook X (Twitter) Instagram
    Trending
    • Most popular stories on GeekWire for the week of May 24, 2026 – GeekWire
    • Growing US reliance on Chinese biotechs prompts national security fears
    • Viking Holdings: At New Highs, And Further To Go (NYSE:VIK)
    • Chelsea Keep or Dump: How can Blues help Xabi Alonso?
    • 2026 Cracker Barrel 400 odds, predictions, time: NASCAR at Nashville picks from proven model
    • This extravagant gaming laptop could ruin other screens for you
    • Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
    • World Health Organization hails recovery of five Ebola patients | Ebola News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

    adminBy adminMay 1, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMay 01, 2026Supply Chain Attack / Malware

    Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

    A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, GitHub Actions tampering, and SSH persistence.

    The activity has been attributed to the GitHub account “BufferZoneCorp,” which has published a set of repositories that are associated with malicious Ruby gems and Go modules. As of writing, the packages have been yanked from RubyGems, and the Go modules have been blocked. The names of the libraries are listed below –

    • Ruby:
      • knot-activesupport-logger
      • knot-devise-jwt-helper
      • knot-rack-session-store
      • knot-rails-assets-pipeline
      • knot-rspec-formatter-json
      • knot-date-utils-rb (Sleeper gem)
      • knot-simple-formatter (Sleeper gem)
    • Go:
      • github[.]com/BufferZoneCorp/go-metrics-sdk
      • github[.]com/BufferZoneCorp/go-weather-sdk
      • github[.]com/BufferZoneCorp/go-retryablehttp
      • github[.]com/BufferZoneCorp/go-stdlib-ext
      • github[.]com/BufferZoneCorp/grpc-client
      • github[.]com/BufferZoneCorp/net-helper
      • github[.]com/BufferZoneCorp/config-loader
      • github[.]com/BufferZoneCorp/log-core (Sleeper module)
      • github[.]com/BufferZoneCorp/go-envconfig (Sleeper module)

    The identified packages masquerade as recognizable and well-known modules like activesupport-logger, devise-jwt, go-retryablehttp, grpc-client, and config-loader so as to evade detection and trick users into downloading them.

    Cybersecurity

    “The account is part of a software supply chain campaign targeting developers, CI runners, and build environments across two ecosystems,” Socket security researcher Kirill Boychenko said in an analysis published today.

    The Ruby gems are designed to automate credential theft during install time, harvesting environment variables, SSH keys, AWS secrets, .npmrc, .netrc, GitHub CLI configuration, and RubyGems credentials. The stolen data is then exfiltrated to an attacker-controlled Webhook[.]site endpoint.

    On the other hand, the Go modules harbor broader capabilities to tamper with GitHub Actions workflows, plant fake Go wrappers, steal developer data, and add a hard-coded SSH public key to “~/.ssh/authorized_keys” for remote access to the compromised host. The modules do not all have the same payload; instead, they are spread across the cluster.

    “The module executes through init(), detects GITHUB_ENV and GITHUB_PATH, sets HTTP_PROXY and HTTPS_PROXY, writes a fake go executable into a cache directory, and appends that directory to the workflow path so the wrapper is selected before the real binary,” Boychenko explained.

    “That wrapper can then intercept or influence later go executions while still passing control to the legitimate binary to avoid breaking the job.”

    Users who have installed the packages are advised to remove them from their systems, review for signs of access to sensitive files or unauthorized changes to “~/.ssh/authorized_keys,” rotate exposed credentials, and inspect network logs for outbound HTTPS traffic to the exfiltration point.

    Credential Exploit Gems Modules Pipelines poisoned Ruby Theft
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleDesign’s next era is about making people feel seen
    Next Article Do You Need Aluminum Luggage? (2026): Rimowa, Away, Carl Friedrik
    admin
    • Website

    Related Posts

    Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

    May 31, 2026

    PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

    May 30, 2026

    ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

    May 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Most popular stories on GeekWire for the week of May 24, 2026 – GeekWire

    Growing US reliance on Chinese biotechs prompts national security fears

    Viking Holdings: At New Highs, And Further To Go (NYSE:VIK)

    Chelsea Keep or Dump: How can Blues help Xabi Alonso?

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by