RubyGems is a technology platform tracked across 10 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed February 16, 2026; most recent activity July 24, 2026.
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A supply chain attack named SleeperGem has been identified targeting the RubyGems ecosystem, exploiting dormant maintainer accounts to publish a malicious gem called git_credential_manager. This gem, which has already…
Databricks is investigating a potential security compromise linked to the TeamPCP supply chain attack. This incident follows a notification from International Cyber Digest, which indicated that Databricks was alerted…
A supply chain attack has compromised RubyGems with 136 malicious packages that deploy an XMRig Monero miner. This attack leverages SSH to propagate itself, affecting developer machines and consuming their computing…
RubyGems has halted new user sign-ups after a malicious attack on May 11, 2026, which involved the publication of hundreds of malicious packages targeting its staff. The malicious code aimed to execute cross-site…
On June 11, 2026, RapidFort announced the launch of RapidFort Curated Libraries, a catalog of malware-scanned open-source libraries aimed at preventing supply chain malware from infiltrating development pipelines. The…
On June 26, 2026, Private Packagist announced enhancements to its malware blocking capabilities for Composer users, particularly those using version 2.10. The updates prevent the installation of flagged malware…
The Biden administration is considering new regulations for AI models, particularly those with potential cybersecurity implications. Secretary Mayorkas emphasized the need for a unified federal approach to prevent a…
The RubyGems Fracture incident, occurring from September 10-18, 2025, involved a contentious takeover of the RubyGems GitHub repository by Ruby Central, leading to the removal of several long-time maintainers. The…
Open source registries are experiencing significant financial difficulties, which are hindering their ability to implement essential security measures. Michael Winser, co-founder of the Alpha-Omega project under the…