• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
rubygems suspends new signups after hundreds of malicious packages are

RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded

You are here: Home / General Cyber Security News / RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
May 12, 2026

RubyGems, the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a “major malicious attack.”

“We’re dealing with a major malicious attack on Ruby Gems right now,” Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. “Signups are paused for the time being. Hundreds of packages involved – mostly targeting us, but some carrying exploits.”

Visitors to RubyGems’ sign up page are now greeted with the message: “New account registration has been temporarily disabled.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Mend.io, which secures RubyGems, said it intends to release more details once the incident is contained. It’s currently not known who is behind the attack.

Cybersecurity

The development comes as software supply chain attacks targeting the open-source ecosystems have been on the rise, with threat actors like TeamPCP compromising widely used packages to distribute credential-stealing malware capable of harvesting sensitive data and allowing the attackers to expand their reach.

In a report published Monday, Google said the credentials stolen from affected environments have been monetized through partnerships with ransomware and data theft extortion groups.

(This is a developing story. Please check back for more details.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «new trickmo variant uses ton c2 and socks5 to create New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
  • New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
  • Webinar: What the Riskiest SOC Alerts Go Unanswered – and How Radiant Security Can Help
  • Why Agentic AI Is Security’s Next Blind Spot
  • Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
  • Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
  • OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation
  • iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android
  • TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
  • cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

Copyright © TheCyberSecurity.News, All Rights Reserved.