# sonatype-2020-1222

ruby-bitcoin, pretty_color - Embedded Malicious Code (Cryptocurrency stealing malware)

Published Dec 14, 2020

[blog.sonatype.com](https://blog.sonatype.com/rubygems-laced-with-bitcoin-stealing-malware) [rubygems/rubygems.org](https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#08-dec-2020)

### sonatype-2020-1222 Security Details

**CVE ID** sonatype-2020-1222  
**CWE** N/A  
**CVE Description** ruby-bitcoin, pretty_color - Embedded Malicious Code (Cryptocurrency stealing malware)  
**Published** Dec 14, 2020  
**CVSS Score & Severity** 10.0 Critical  
**CVSS Vector** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H  
**EPSS Score** 0%  
**Malware** malware  
**KEV Status** Not in KEV Catalog: No known exploits  
**Affected Ecosystems** affected  
**Source** Sonatype

### References

[blog.sonatype.com](https://blog.sonatype.com/rubygems-laced-with-bitcoin-stealing-malware) THIRD_PARTY  
[GitHub · rubygems/rubygems.org](https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#08-dec-2020) THIRD_PARTY
