Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Hundreds of Malicious Packages Force RubyGems to Suspend Registrations

More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users.

Software security

New account registrations on RubyGems.org, the official Ruby gem hosting service, have been suspended after threat actors published hundreds of malicious packages. 

RubyGems maintainers announced on May 12 that registrations have been temporarily disabled due to a “DDoS attack”. 

Nearly 24 hours later, registrations are still disabled and will likely remain closed for another 2-3 days until account creation rate limiting can be tightened and WAF protection is enabled.

According to RubyGems maintainers, the service was targeted in “spam activity” that involved bot accounts pushing more than 500 junk packages, including ones carrying exploits. 

The malicious packages have been removed from the registry, and existing packages have not been compromised.

An investigation into the incident is ongoing, but at this point it appears that end users were not targeted. 

Advertisement. Scroll to continue reading.

“Gem installs and pushes for existing users are unaffected,” RubyGems said on its status page. 

Maciej Mensfeld of the RubyGems security team noted in a post on X that the attack appears to have targeted RubyGems itself, with the attackers attempting XSS attacks and data exfiltration.

“My worry with this RubyGems attack: it could be masking something more sophisticated. No proof, just a security researcher’s intuition. Hope I’m wrong,” Mensfeld said.

Related: TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

Related: Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

Related: Claude Mythos Finds Only One Curl Vulnerability; Experts Divided on What It Really Means

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.