Categories: Insur. Cyber

RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded


Ravie LakshmananMay 12, 2026Supply Chain Attack / Software Security

RubyGemsthe standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a “major malicious attack.”

“We’re dealing with a major malicious attack on Ruby Gems right now,” Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. “Signups are paused for the time being. Hundreds of packages involved – mostly targeting us, but some carrying exploits.”

Visitors to RubyGems’ sign up page are now greeted with the message: “New account registration has been temporarily disabled.”

Mend.io, which secures RubyGems, said it intends to release more details once the incident is contained. It’s currently not known who is behind the attack.

The development comes as software supply chain attacks targeting open-source ecosystems have been on the rise, with threat actors like TeamPCP compromising widely used packages to distribute credential-stealing malware capable of harvesting sensitive data and allowing the attackers to expand their reach.

In a report published Monday, Google said the credentials stolen from affected environments have been monetized through partnerships with ransomware and data theft extortion groups.

(This is a developing story. Please check back for more details.)



Source link
nabeelhassan565@gmail.com

Share
Published by
nabeelhassan565@gmail.com

Recent Posts

It’s a Good Thing? Martha Stewart to Get Into Home Insurance With Hint

Hint, a self-described “home management platform,” has launched with a $10 million seed round of…

4 minutes ago

CFC appoints former Truist head as chair

Specialist insurer CFC on Monday said it has named former Truist Insurance head John Howard…

37 minutes ago

Willis names growth leaders – Business Insurance

Willis, the retail broking unit of Willis Towers Watson, said Monday it appointed former Marsh…

2 heures ago

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

Ravie LakshmananMay 18, 2026Cybersecurity / Hacking Monday opens with a trust problem. A mail server…

2 heures ago

Lloyd’s boss concerned over rapidly falling rates

Rachel Turk, Lloyd’s chief of performance and strategy, said market rates are falling faster than…

3 heures ago

Meilleure vitamine C : 7 compléments analysés (2026)

Notre méthodologie Ce comparatif a été réalisé en analysant les fiches produit, les tableaux nutritionnels,…

3 heures ago