Security researchers documented updated universal gadget chains that can achieve remote command execution when Ruby applications call Marshal.load on attacker-controlled data. A Ruby 3.4 proof of concept autoloads RubyGems’ vendored Gem::URI namespace, removing the former requirement for net/http to have been loaded, and substitutes commonly available rake or make binaries for the prior zip dependency. It also uses UncaughtThrowError to suppress the post-exploitation exception; its Gem::Source::Git popen sink can generate outbound network traffic and modify the filesystem. The technique builds on earlier universal Ruby 2.x deserialization research.
New analysis finds that risk is not limited to classes implementing documented custom Marshal hooks such as marshal_load, _load, and _load_data. During object reconstruction, Marshal.load can implicitly invoke attacker-influenced hash, eql?, <=>, to_str, to_s, and respond_to? methods, creating broad gadget-discovery opportunities even in Ruby 4.0.6 processes started with --disable-gems. Removing RubyGems .rz Marshal-spec support may reduce attack surface but does not eliminate it; organizations should treat untrusted Marshal input as unsafe, eliminate its use at trust boundaries, and audit deserialization paths and exposed RubyGems-dependent applications.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Luke Jahnke published a universal Ruby 3.4 deserialization gadget chain that can execute commands when an application loads attacker-controlled Marshal data. The payload autoloads RubyGems' Gem::URI namespace, uses make or rake as execution candidates, and demonstrates writing id output to /tmp/marshal-poc.
Trail of Bits' 2024 RubyGems.org security review identified finding TOB-RGM-9 concerning compressed Marshaled specification data served in .rz files. The finding recommended removing the associated functionality or moving to a safer serialization format such as JSON.
A universal Ruby deserialization chain in 2022 used historical Gem::Specification._load behavior. That behavior has since changed and no longer calls to_s on recovered data.
An analysis identified six implicit method-dispatch paths during Marshal.load—hash, eql?, <=>, to_str, to_s, and respond_to?—in addition to documented custom-marshalling hooks. A Ruby 4.0.6 --disable-gems survey found these implicit behaviors available across substantially more classes than explicit marshal_load, _load, and _load_data hooks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
elttam.com
Open sourcenastystereo.com
Open sourcedevcraft.io
Open sourceelttam.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.