As cited
Copy frozen at (site build).
breaches incidents
Risky Bulletin: RubyGems disables sign-ups after attack on staff
RubyGems disabled new user sign-ups following a targeted attack on its staff that resulted in the publication of hundreds of malicious packages across two days. The packages contained code designed to execute cross-site scripting attacks and exfiltrate data from developer systems.
Why it matters: Ruby developers relying on RubyGems face supply chain risk from compromised packages; practitioners should review recent gem installations and monitor for suspicious activity from dependencies.
- Source published
- First seen by Cybersecurity Tracker