HomeSecurityRubyGems suspends account registrations due to attack

RubyGems suspends account registrations due to attack

RubyGems , the package manager for the Ruby programming language , has temporarily suspended account registrations due to a “major malicious attack.”

RubyGems

“We are facing a large malicious attack on RubyGems right now,” said Maciej Mensfeld, senior product manager for software supply chain security at Mend.io.“Account registrations are currently suspended. Hundreds of packages are involved – mostly targeting us, but some carry exploits.”

Visitors to the RubyGems registration page see the message: “New account registration has been temporarily disabled.”

See also: Claude Code: Fake installers install malware

Mend.io, which works on RubyGems security, said it plans to release more details once the incident is contained. It is not currently known who is behind the attack.

RubyGems attack and other supply chain attacks

This development comes at a time when software supply chain attacks targeting open source ecosystems have increased, with threat actors such as TeamPCP compromising widely used packages to distribute malware that steals credentials and other data.

See also: Mini Shai-Hulud Worm: Infects TanStack, Mistral AI and other Packages

RubyGems suspends account registrations due to attack

In a report published on Monday, Google said that credentials stolen from affected environments have been commercialized through partnerships with data extortion and ransomware groups.

The RubyGems case is a reminder that open source ecosystems are now one of the main targets of cybercriminals. The temporary suspension of new account creation shows the amount of pressure that software distribution platforms, especially when thousands of developers and businesses depend on third-party packages every day to develop applications. The fact that hundreds of packages appear to be involved in the attack raises concerns about the possible spread of malicious code on a wider scale.

See also: cPanel vulnerability used to distribute Filemanager Backdoor

At the same time, supply chain attacks are emerging as one of the most dangerous trends in cybersecurity. Attackers are no longer targeting end users exclusively, but are attempting to infect the software development chain, gaining access to thousands of systems through popular packages and libraries. Google’s recent reports of collaborations between credential theft, ransomware, and data extortion groups confirm that the financial incentive behind these attacks is increasing dramatically, making open source security a critical issue for the entire technology industry.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS