Bitcoin Forum
May 07, 2024, 11:05:01 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: 2 new Rubygems package link with malicous crypto clipboard malware  (Read 95 times)
Dave1 (OP)
Hero Member
*****
Offline Offline

Activity: 1302
Merit: 522



View Profile
December 16, 2020, 09:30:22 PM
Merited by LoyceV (2), Halab (2), btc_angela (1)
 #1

For Rubygems developers:

There is a new malicious Rubygems packages recently found to include a malicious code, that acts as a clipboard malware:

- pretty_color-0.8.1.gem
- ruby-bitcoin-0.0.20.gem

So as this is a clipboard malware, the code once installed will be persistence and will monitor your clipboard for any bitcoin, ethereum and monero addresses. And once you copied it and paste it to your wallet, the malware will replace it with their own addresses. So far the following addresses have been identified:

  • Bitcoin: bc1qgmem0e4mjejg4lpp03tzlmhfpj580wv5hhkf3p
  • Ethereum: 0xcB56f3793cA713813f6f4909D7ad2a6EEe41eF5e
  • Monero: 467FN8ns2MRYfLVEuyiMUKisvjz7zYaS9PkJVXVCMSwq37NeesHJpkfG44mxEFHu8Nd9VDtcVy4kM9i VD7so87CAH2iteLg



So to everyone, be careful doing copy and paste and you have to check everything. For reference, you can read @LoyceV How to lose your Bitcoins with CTRL-C CTRL-V.

https://blog.sonatype.com/rubygems-laced-with-bitcoin-stealing-malware
https://www.bleepingcomputer.com/news/security/malicious-rubygems-packages-used-in-cryptocurrency-supply-chain-attack/

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
1715079901
Hero Member
*
Offline Offline

Posts: 1715079901

View Profile Personal Message (Offline)

Ignore
1715079901
Reply with quote  #2

1715079901
Report to moderator
You can see the statistics of your reports to moderators on the "Report to moderator" pages.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715079901
Hero Member
*
Offline Offline

Posts: 1715079901

View Profile Personal Message (Offline)

Ignore
1715079901
Reply with quote  #2

1715079901
Report to moderator
1715079901
Hero Member
*
Offline Offline

Posts: 1715079901

View Profile Personal Message (Offline)

Ignore
1715079901
Reply with quote  #2

1715079901
Report to moderator
btc_angela
Hero Member
*****
Offline Offline

Activity: 2604
Merit: 542



View Profile
December 17, 2020, 02:25:32 AM
 #2

Probably it contributed to the widespread or spike of crypto related clipboard malware recently. As it is really hard to detect in the beginning. And the best weapons against this kind of attack, is to verify and check every bitcoin addresses we're using specially if we are going to used copy and paste function.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Cryptomint9
Member
**
Offline Offline

Activity: 76
Merit: 23


View Profile
December 17, 2020, 04:07:08 AM
 #3

This is happening. Be careful all of you. Day by day new and new problems are coming.
cryptomaniac_xxx
Hero Member
*****
Offline Offline

Activity: 1498
Merit: 566



View Profile
December 17, 2020, 12:32:13 PM
 #4

Just imagine if this clipboard wasn't discovered by cyber investigators, the damage it can be done and it could be many in crypto space falling for this scheme. So it's good that it has been stop on it's track for now. But we shouldn't get complacent as these criminals will find a new way to exploit the other systems to inject malicious codes.

.
 airbet 
██
██
██
██
██
██
██
██
██
██
██
██
██
 .

▄████▄▄▄██████▄
███████████████
███████████████
███████▀▀▀▀████
██████████████
▀███▀███████▄██
██████████▄███
██████████████
███████████████
███████████████
██████████████
█████▐████████
██████▀███████▀
▄███████████████▄
████████████████
█░██████████████
████████████████
████████████████
█████████████████
█████████████████
███████░█░███████
████████████████
█████████████████
██████████████░█
████████████████
▀███████████████▀
.
.
.
.
██▄▄▄
████████▄▄
██████▀▀████▄
██████▄░░████▄
██████████████
████████░░▀███▌
░████████▄▄████
██████████████▌
███░░░█████████
█████████░░░██▀
░░░███████████▀
██████░░░██▀
░░▀▀███▀

   
|.
....
██
██
██
██
██
██
██
██
██
██
██
██
██
.
 PLAY NOW 
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!