RubyGems Registry Attack: 500+ Malicious Packages Pulled

CommentarySupply chain
All News

RubyGems temporarily suspended new account registrations on May 12 after a coordinated spam-publishing campaign pushed over 500 malicious packages through newly registered accounts. More than 120 packages were pulled immediately, bot accounts were blocked, and the registry confirmed the attack had stopped by May 13. Signups remain closed while RubyGems coordinates with Fastly to enable WAF protection and tighten rate limiting, a process expected to take two to three days.

This is a supply chain risk worth keeping on your radar, particularly if your stack has any Ruby dependencies. The packages in this campaign were largely junk spam, but some carried active exploits, and the broader trend is not slowing down. Threat actors like TeamPCP have been consistently targeting open-source package registries to distribute credential-stealing malware, with stolen credentials being funneled into ransomware and extortion operations. The registry is the new perimeter for supply chain attackers, and RubyGems is not the first to be hit this way and will not be the last.

If you manage Ruby dependencies, now is a good time to audit your Gemfile.lock, verify package publishers, and make sure your CI pipeline flags newly introduced or recently updated gems for review before they reach production.