The rest-client RubyGems Supply Chain Attack
Updated 5 Oct 2026 · Incident date 14 Aug 2019 · RubyGems
rest-client 1.6.9 -> 1.6.10, 1.6.11, 1.6.12, 1.6.13lib/restclient/request.rbOn 14 August 2019, an attacker published rest-client 1.6.10, 1.6.11, 1.6.12 and 1.6.13 on RubyGems.org with a code-execution backdoor. The CVE is CVE-2019-15224. The safe versions are 1.6.9 and earlier, and 1.6.14 and later.
The GitHub advisory counts about 113 million total downloads for the gem before the discovery. The bad releases had about 1,000 downloads.
What happened
An attacker used a maintainer's RubyGems account to publish four malicious releases. SecurityWeek reports that the account used an insecure, reused password that had leaked in other breaches. The maintainers state that the attack happened on 14 August 2019. A researcher found and reported it on 19 August 2019, and RubyGems yanked the versions and locked the account that day. The researcher is named as Jussi Koljonen in the SecurityWeek report.
The backdoor ran only when a Rails app started in production. It waited 900 seconds, then fetched Ruby code from a Pastebin URL and ran it. It also sent data to mironanoru.zzz.com.ua. The maintainers' notes say it tried to take credentials from session cookies and to send environment variables. SecurityWeek reports that it collected user names, passwords and other secrets from the host.
The same attacker also published malicious versions of other gems. The GitHub advisory names cron_parser 1.0.13 and 1.0.14, and also coin_base, blockchain_wallet, awesome-bot, doge-coin, capistrano-colors, bitcoin_vanity, lita_coin, coming-soon and omniauth_amazon.
Vigilance compares the version you trust with the new one. Version 1.6.10 added code that fetches and runs outside Ruby code, and Vigilance reports the file that gained that capability. See the scan block below.
Affected versions
rest-client1.6.10, 1.6.11, 1.6.12 and 1.6.13. Yanked from RubyGems.- Safe: 1.6.9 or earlier, and 1.6.14 or later. The maintainers released 1.6.14 as a copy of 1.6.9. The GitHub advisory also names 1.7.0.
- Other gems from the same attacker: cron_parser 1.0.13 and 1.0.14, bitcoin_vanity 4.3.3, lita_coin 0.0.3, coming-soon 0.2.8, omniauth_amazon 1.0.1, awesome-bot 1.18.0, doge-coin 1.0.2, capistrano-colors 0.5.5, and coin_base and blockchain_wallet in several versions.
Indicators of compromise
- Server:
mironanoru.zzz.com.ua. - A request to a Pastebin URL from a Rails process about 900 seconds after start in production.
rest-client (1.6.10)to(1.6.13)in aGemfile.lock.- Unexpected CPU use. The maintainers' notes say it reportedly mined cryptocurrency.
How to check
The maintainers give this command to find affected lock files.
grep --include='Gemfile.lock' -r . -e 'rest-client (1.6.1[0123])'
Check the installed gem with:
gem list rest-client
Also search proxy logs for mironanoru.zzz.com.ua and for Pastebin requests from production servers.
What to do now
- Move rest-client to 1.6.14 or a later version. Run
bundle update rest-clientand check the lock file. - Check the other gems in the list above and remove them if you use them.
- If a bad version ran in production, treat the server as compromised. Rotate every secret in its environment variables and every credential that the app handled.
- Block the server named above.
- Use two-factor sign-in on your RubyGems account, as the rest-client maintainers now require.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 38 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE lib/restclient/request.rb It downloads from the internet, reads saved passwords and access keys and runs other programs.
Frequently asked questions
Which rest-client versions were backdoored?
Versions 1.6.10, 1.6.11, 1.6.12 and 1.6.13 were backdoored. Use 1.6.9 or earlier, or 1.6.14 or later.
How do I find out if my app used a malicious rest-client?
Search every Gemfile.lock for rest-client 1.6.10 through 1.6.13. The maintainers give a grep command for this in their issue 713.
Sources
More supply chain attacks
- SleeperGem dormant-maintainer RubyGems hijacks 18 Jul 2026
- strong_password gem hijack (CVE-2019-13354) 25 Jun 2019
- bootstrap-sass RubyGems backdoor 26 Mar 2019
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.