Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
final-poc-usaRubyGems
Malicious code in final-poc-usa (RubyGems) Remove it immediately and rotate any exposed credentials.
MAL-2026-6118
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
gem uninstall final-poc-usa
What this malware does
The OpenSSF Package Analysis project identified 'final-poc-usa' @ 0.99800.0 (rubygems) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Malicious versions
0.99800.0
Indicators of compromise (SHA-256)
6cc39e355e69ec11b0532da1e2b2a418601a4c5594b100ba6f054f0e52be44be
Frequently asked questions
No. final-poc-usa on RubyGems has been identified as a malicious package (version 0.99800.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Credits
- OpenSSF: Package Analysis · finder
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection