Hacker News new | ask | show | jobs
by joekrill 2631 days ago
5th Paragraph in:

> The backdoor was wisely hidden in the 3.2.0.3 version that was only published to RubyGems and no source of the malicious version existed on the GitHub repository and allowed remote attackers to dynamically execute code on servers hosting the vulnerable versions.