Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-06 · updated: 2026-10-06 · tags: [incident, global, supply-chain] · confidence: high · severity: high · affected_sectors: [global] · au_impact: true

The supply-chain watch's 5 October human-verified batch flags a large coordinated attack on RubyGems involving more than 40 packages, all marked critical and affecting all versions. The packages — including web3-sign-helper, crypto-key-utils, bip39-wordlist-utils, eth-address-utils, lightning-invoice-utils, wallet-backup-tool and ethereum-tx-helper — were published by the reqthrottle_3474 RubyGems account and execute an install-time payload (rubygems-btc-shell) designed to harvest cryptocurrency wallet keys, seed phrases and related secrets, blending typosquatted and lookalike naming (e.g. bitciin, crypti-toolbox, etherdum.rb) with functional-sounding utility names. The campaign is distinct from the npm @angular/core typosquat wave of the same day, and every verified asset carries a human-verified malicious designation from OpenSourceMalware's four-stage review. Why it matters: install-time credential harvesting on a package index used by financial and crypto tooling means any developer grip of these names in a dependency graph — or a seed phrase typed into a compromised tool — is an active credential-loss incident; the wave keeps the package-typosquat pipeline a standing risk for AU/NZ developers.

Attribute Detail
Sector Global (Macro)
Date 2026-10-06
Source OpenSourceMalware — web3-sign-helper
Reliability Tier 2