The rest-client RubyGems Supply Chain Attack

Updated 5 Oct 2026 · Incident date 14 Aug 2019 · RubyGems

Packagerest-client 1.6.9 -> 1.6.10, 1.6.11, 1.6.12, 1.6.13
Filelib/restclient/request.rb

On 14 August 2019, an attacker published rest-client 1.6.10, 1.6.11, 1.6.12 and 1.6.13 on RubyGems.org with a code-execution backdoor. The CVE is CVE-2019-15224. The safe versions are 1.6.9 and earlier, and 1.6.14 and later.

The GitHub advisory counts about 113 million total downloads for the gem before the discovery. The bad releases had about 1,000 downloads.

What happened

An attacker used a maintainer's RubyGems account to publish four malicious releases. SecurityWeek reports that the account used an insecure, reused password that had leaked in other breaches. The maintainers state that the attack happened on 14 August 2019. A researcher found and reported it on 19 August 2019, and RubyGems yanked the versions and locked the account that day. The researcher is named as Jussi Koljonen in the SecurityWeek report.

The backdoor ran only when a Rails app started in production. It waited 900 seconds, then fetched Ruby code from a Pastebin URL and ran it. It also sent data to mironanoru.zzz.com.ua. The maintainers' notes say it tried to take credentials from session cookies and to send environment variables. SecurityWeek reports that it collected user names, passwords and other secrets from the host.

The same attacker also published malicious versions of other gems. The GitHub advisory names cron_parser 1.0.13 and 1.0.14, and also coin_base, blockchain_wallet, awesome-bot, doge-coin, capistrano-colors, bitcoin_vanity, lita_coin, coming-soon and omniauth_amazon.

Vigilance compares the version you trust with the new one. Version 1.6.10 added code that fetches and runs outside Ruby code, and Vigilance reports the file that gained that capability. See the scan block below.

Affected versions

Indicators of compromise

How to check

The maintainers give this command to find affected lock files.

grep --include='Gemfile.lock' -r . -e 'rest-client (1.6.1[0123])'

Check the installed gem with:

gem list rest-client

Also search proxy logs for mironanoru.zzz.com.ua and for Pastebin requests from production servers.

What to do now

  1. Move rest-client to 1.6.14 or a later version. Run bundle update rest-client and check the lock file.
  2. Check the other gems in the list above and remove them if you use them.
  3. If a bad version ran in production, treat the server as compromised. Rotate every secret in its environment variables and every credential that the app handled.
  4. Block the server named above.
  5. Use two-factor sign-in on your RubyGems account, as the rest-client maintainers now require.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old rest-client-1.6.9 --new rest-client-1.6.10
files scanned: 38 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   lib/restclient/request.rb
           It downloads from the internet, reads saved passwords and access keys and runs other programs.

Frequently asked questions

Which rest-client versions were backdoored?

Versions 1.6.10, 1.6.11, 1.6.12 and 1.6.13 were backdoored. Use 1.6.9 or earlier, or 1.6.14 or later.

How do I find out if my app used a malicious rest-client?

Search every Gemfile.lock for rest-client 1.6.10 through 1.6.13. The maintainers give a grep command for this in their issue 713.

Sources

  1. github.com/rest-client/rest-client/issues/713
  2. github.com/advisories/GHSA-333g-rpr4-7hxq
  3. securityweek.com/backdoor-found-rest-client-ruby-gem/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free