Hundreds of Malicious Packages Force RubyGems to Suspend Registrations

https://www.securityweek.com/wp-content/uploads/2026/04/coding-vulnerability-software-development.jpeg

Malware & Threats

More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users.

New account registrations on RubyGems.org, the official Ruby gem hosting service, have been suspended after threat actors published hundreds of malicious packages.

RubyGems maintainers announced on May 12 that registrations have been temporarily disabled due to a “DDoS attack”.

Nearly 24 hours later, registrations are still disabled and will likely remain closed for another 2-3 days until account creation rate limiting can be tightened and WAF protection is enabled.

According to RubyGems maintainers, the service was targeted in “spam activity” that involved bot accounts pushing more than 500 junk packages, including ones carrying exploits.

The malicious packages have been removed from the registry, and existing packages have not been compromised.

An investigation into the incident is ongoing, but at this point it appears that end users...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more