Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Hundreds of Malicious Packages Force RubyGems to Suspend Registrations

More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users.

Software security

New account registrations on RubyGems.org, the official Ruby gem hosting service, have been suspended after threat actors published hundreds of malicious packages. 

RubyGems maintainers announced on May 12 that registrations have been temporarily disabled due to a “DDoS attack”. 

Nearly 24 hours later, registrations are still disabled and will likely remain closed for another 2-3 days until account creation rate limiting can be tightened and WAF protection is enabled.

According to RubyGems maintainers, the service was targeted in “spam activity” that involved bot accounts pushing more than 500 junk packages, including ones carrying exploits. 

The malicious packages have been removed from the registry, and existing packages have not been compromised.

An investigation into the incident is ongoing, but at this point it appears that end users were not targeted. 

Advertisement. Scroll to continue reading.

“Gem installs and pushes for existing users are unaffected,” RubyGems said on its status page. 

Maciej Mensfeld of the RubyGems security team noted in a post on X that the attack appears to have targeted RubyGems itself, with the attackers attempting XSS attacks and data exfiltration.

“My worry with this RubyGems attack: it could be masking something more sophisticated. No proof, just a security researcher’s intuition. Hope I’m wrong,” Mensfeld said.

Related: TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

Related: Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

Related: Claude Mythos Finds Only One Curl Vulnerability; Experts Divided on What It Really Means

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.