Threats · 124 days ago
The real break is at the registry control plane. This attack hit RubyGems' own abuse defenses, so checking local gems misses the weak point: whether the service can still block mass signups, junk uploads, and hostile account creation.
RubyGems suspended new registrations after bots pushed more than 500 malicious or junk packages. The registry says existing gems and installs were not compromised, and it is tightening rate limits and enabling WAF protection after reports of attempted XSS and data exfiltration against the service itself.
That leaves a second-order risk: sustained registry abuse can become a staging ground for future supply-chain tampering even if today's packages are removed. The issue is not the current gem corpus, but whether the registry can keep malicious uploads from landing at scale.
3 sources covering this story
Risky Bulletin: Damaging worm rips through npm ecosystem
RubyGems disables sign-ups after an attack on staff, Instructure paid the ransom, the Gentlemen ransomware operation gets hacked, and anot [Read More
Hundreds of Malicious Packages Force RubyGems to Suspend Registrations
More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users.
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
RubyGems halted new registrations after a major attack involving hundreds of malicious packages, increasing supply chain risks.
Part of the PlainSec briefing for 2026-05-13