malware rubygems

fastlane-plugin-run_tests_firebase_testlab

discovered 2026-07-19

Established RubyGems package (574,661 total downloads) belonging to an entirely different maintainer than git_credential_manager/Dendreo. Received a new malicious version around the same time, pushing the same git_credential_manager dependency chain. Its involvement shows the compromise spans at least two separate long-dormant RubyGems maintainer accounts reactivated within hours of each other. Exact malicious version number not disclosed in source.

Threat types

other

Malicious versions

  • unknown

Techniques

Read the full analysis →