Risky Bulletin Newsletter
May 13, 2026
Risky Bulletin: RubyGems disables sign-ups after attack on staff
Presented by
News Editor
The RubyGems package repository has disabled new user sign-ups after a malicious attack on Monday targeted its engineers and staff.
Hundreds of malicious packages were published on Monday and then again on Tuesday.
The packages contained malicious code aimed at RubyGems developers. The code tried to execute cross-site scripting attacks and steal data from their systems.