Mining for Malicious Ruby Gems
blog.reversinglabs.com
blog.reversinglabs.com
Very rare indeed. I suppose every package had their own BTC address. I wonder how much they got away with.
But I thought rubygems does a similarity check for names and reject or flag them for manual verification if the name is too similar to an existing one?
action-mailer_cache_delivery
action-mailer-cache-delivery
actionmailercachedelivery
act-ion-ma-iler_c-ache-deli_very
Should resolve to the same entry in RubyGems.I would also support this usage in `require` lines.
The "experts-exchange" (or "pen-is-mightier") problem is tiny compared to the frustration and security risk of the present policy.