The strong_password RubyGems Supply Chain Attack

Updated 5 Oct 2026 · Incident date 25 Jun 2019 · RubyGems

Packagestrong_password 0.0.6 -> 0.0.7 (fixed in 0.0.8)
Filelib/strong_password/strength_checker.rb

strong_password 0.0.7 on RubyGems contained code that downloaded and ran a stranger's code. It has the identifier CVE-2019-13354. Version 0.0.6 is clean. The attacker released 0.0.7 on 25 June 2019.

The original maintainer, Brian McManus, lost control of his RubyGems account. The source repository on GitHub showed no change.

What happened

An attacker took over the gem owner's account and published version 0.0.7 with a hidden backdoor. The researcher who found it reports that the account was compromised through credential reuse across breached services and no two-factor authentication.

The new code was added at the end of lib/strong_password/strength_checker.rb. It started a background thread. The thread waited a random time, checked that the app ran in production, and then fetched code from a Pastebin post and ran it with eval. Errors were silently ignored. The code also sent the URL_HOST value to a remote domain. A second part added Rack middleware that decoded and ran Base64 commands sent in an HTTP cookie.

The researcher found the problem on 3 July 2019 by comparing the code on RubyGems.org with the GitHub repository. GitHub showed no recent change. The published gem had extra code at the end of the file. RubyGems.org yanked the release, locked the attacker's account, and restored McManus as owner. SecurityWeek reports 537 downloads of 0.0.7 before removal. Snyk also published an analysis.

Affected versions

The advice from Rubysec was to downgrade to 0.0.6 at once.

Indicators of compromise

How to check

List the installed version, then search the gem files for the Pastebin address. Neither command runs the gem.

gem list strong_password
bundle list | grep strong_password
grep -rn 'pastebin' "$(bundle exec gem contents strong_password | head -1 | xargs dirname)"

Also check Gemfile.lock for the version.

grep -n strong_password Gemfile.lock

What to do now

  1. Pin strong_password to 0.0.6 or update to a fixed release, and run bundle update strong_password.
  2. If a production app ran 0.0.7, treat the server as compromised because the code ran remote commands. Rotate secrets, keys, and database credentials.
  3. Search outbound logs for pastebin.com and smiley.zzz.com.ua.
  4. Turn on two-factor authentication for every RubyGems account you own. Use a different password for each service.
  5. Compare gem contents on RubyGems.org with the source repository when you audit dependencies.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old strong_password-0.0.6 --new strong_password-0.0.7
files scanned: 12

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    lib/strong_password/strength_checker.rb
           It now downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which strong_password version is malicious?

Version 0.0.7, released on 25 June 2019 and tracked as CVE-2019-13354. Version 0.0.6 is clean.

What did the strong_password backdoor do?

It started a background thread that fetched code from a Pastebin post and ran it with eval in production. It also added Rack middleware that ran commands sent in a cookie.

How was the strong_password gem hijacked?

The attacker took over the owner's RubyGems account. The researcher attributes this to credential reuse and no two-factor authentication.

Sources

  1. withatwist.dev/strong-password-rubygem-hijacked.html
  2. securityweek.com/malicious-code-planted-strongpassword-ruby-gem/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free