A backdoor in the Ruby gem bootstrap-sass
It is now apparently Ruby’s turn, with a new report of a remote-execution backdoor being inserted, briefly, into a popular gem that is installed by some sites using the Ruby on Rails web-application framework. Version 3.2.0.2 of bootstrap-sass gem was removed from the RubyGems repository, presumably by the malicious actor(s), sometime prior to March 26. Securing those mechanisms will go a long way toward stopping the next web-application backdoor.
Source: lwn.net