The strong_password RubyGems Supply Chain Attack
Updated 5 Oct 2026 · Incident date 25 Jun 2019 · RubyGems
strong_password 0.0.6 -> 0.0.7 (fixed in 0.0.8)lib/strong_password/strength_checker.rbstrong_password 0.0.7 on RubyGems contained code that downloaded and ran a stranger's code. It has the identifier CVE-2019-13354. Version 0.0.6 is clean. The attacker released 0.0.7 on 25 June 2019.
The original maintainer, Brian McManus, lost control of his RubyGems account. The source repository on GitHub showed no change.
What happened
An attacker took over the gem owner's account and published version 0.0.7 with a hidden backdoor. The researcher who found it reports that the account was compromised through credential reuse across breached services and no two-factor authentication.
The new code was added at the end of lib/strong_password/strength_checker.rb. It started a background thread. The thread waited a random time, checked that the app ran in production, and then fetched code from a Pastebin post and ran it with eval. Errors were silently ignored. The code also sent the URL_HOST value to a remote domain. A second part added Rack middleware that decoded and ran Base64 commands sent in an HTTP cookie.
The researcher found the problem on 3 July 2019 by comparing the code on RubyGems.org with the GitHub repository. GitHub showed no recent change. The published gem had extra code at the end of the file. RubyGems.org yanked the release, locked the attacker's account, and restored McManus as owner. SecurityWeek reports 537 downloads of 0.0.7 before removal. Snyk also published an analysis.
Affected versions
- strong_password 0.0.7 (malicious, CVE-2019-13354)
- strong_password 0.0.6 (clean, a plain offline string-scoring library)
The advice from Rubysec was to downgrade to 0.0.6 at once.
Indicators of compromise
- Pastebin URL
https://pastebin.com/raw/xa456PFt - Domain
smiley.zzz.com.ua - A production check of the form
Rails.env[0]=="p"instrength_checker.rb - An HTTP cookie with an
___idparameter that carries Base64 text - The gem uses the Faraday gem to talk to the remote server
How to check
List the installed version, then search the gem files for the Pastebin address. Neither command runs the gem.
gem list strong_password bundle list | grep strong_password grep -rn 'pastebin' "$(bundle exec gem contents strong_password | head -1 | xargs dirname)"
Also check Gemfile.lock for the version.
grep -n strong_password Gemfile.lock
What to do now
- Pin strong_password to 0.0.6 or update to a fixed release, and run
bundle update strong_password. - If a production app ran 0.0.7, treat the server as compromised because the code ran remote commands. Rotate secrets, keys, and database credentials.
- Search outbound logs for
pastebin.comandsmiley.zzz.com.ua. - Turn on two-factor authentication for every RubyGems account you own. Use a different password for each service.
- Compare gem contents on RubyGems.org with the source repository when you audit dependencies.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 12 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED lib/strong_password/strength_checker.rb It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which strong_password version is malicious?
Version 0.0.7, released on 25 June 2019 and tracked as CVE-2019-13354. Version 0.0.6 is clean.
What did the strong_password backdoor do?
It started a background thread that fetched code from a Pastebin post and ran it with eval in production. It also added Rack middleware that ran commands sent in a cookie.
How was the strong_password gem hijacked?
The attacker took over the owner's RubyGems account. The researcher attributes this to credential reuse and no two-factor authentication.
Sources
More supply chain attacks
- SleeperGem dormant-maintainer RubyGems hijacks 18 Jul 2026
- rest-client gem backdoor (CVE-2019-15224) 14 Aug 2019
- bootstrap-sass RubyGems backdoor 26 Mar 2019
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.