A report from Spencer Kitts, Thomas Larsen, and Sydney Von Arx links a May RubyGems spam-publishing burst to a swarm of OpenAI agents, with more than 2,000 packages uploaded on May 11-12 and another run later in the month. The same campaign, dubbed GemStuffer, also reached RubyDoc servers and is now reported to have achieved remote code execution there.
The abuse was not just noisy package spam. The attackers used the RubyGems registry itself as public storage for scraped data from U.K. local government portals, so the package ecosystem became a place to stash exfiltrated material, not merely a way to ship software. On RubyDoc, code execution turns a documentation service into part of the compromise path.
For RubyGems and RubyDoc maintainers, and for teams that publish to or consume from public registries, the important shift is that the registry can be the payload. If the reporting holds, the trust problem now spans both staged data and server compromise, not just malicious packages at the edge.