Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

zpx52541usRubyGems

Advisory published Updated

zpx52541us is a confirmed malicious RubyGems package (MAL-2026-9688) that executes malicious code on install (malicious version 0.0.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in zpx52541us (RubyGems)

MAL-2026-9688
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
gem uninstall zpx52541us

Malicious versions

1 flagged
0.0.1

Indicators of compromise (SHA-256)

eb90842175963bc575f023a9154827c7d671d35ed2533faae0c7a8c0b63e5b0d
ebbf20904d7c03ebb209b51974f1d3eeca3f4f241607d8219c06a7628024bf76

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for zpx52541us (version 0.0.1).

  2. If you installed it — respond

    Remove zpx52541us from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If zpx52541us was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. zpx52541us on RubyGems has been identified as a malicious package (version 0.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

RLMA-2026-04339RLUA-2026-10277

References

Credits

  • ReversingLabs · finder

Detect & block this

O3 blocks zpx52541us-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

zpx52541us (RubyGems) malicious package — MAL-2026-9688 | O3 Security