The supply-chain watch's 5 October human-verified batch flags a large coordinated attack on RubyGems involving more than 40 packages, all marked critical and affecting all versions. The packages — including web3-sign-helper, crypto-key-utils, bip39-wordlist-utils, eth-address-utils, lightning-invoice-utils, wallet-backup-tool and ethereum-tx-helper — were published by the reqthrottle_3474 RubyGems account and execute an install-time payload (rubygems-btc-shell) designed to harvest cryptocurrency wallet keys, seed phrases and related secrets, blending typosquatted and lookalike naming (e.g. bitciin, crypti-toolbox, etherdum.rb) with functional-sounding utility names. The campaign is distinct from the npm @angular/core typosquat wave of the same day, and every verified asset carries a human-verified malicious designation from OpenSourceMalware's four-stage review. Why it matters: install-time credential harvesting on a package index used by financial and crypto tooling means any developer grip of these names in a dependency graph — or a seed phrase typed into a compromised tool — is an active credential-loss incident; the wave keeps the package-typosquat pipeline a standing risk for AU/NZ developers.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-06 |
| Source | OpenSourceMalware — web3-sign-helper |
| Reliability | Tier 2 |