RubyGems Suspends New Signups After Coordinated Attack Pushes Over 500 Malicious Packages
RubyGems temporarily suspended new account registrations after a coordinated bot campaign published more than 500 malicious packages. The packages have since been removed, but the incident highlights growing pressure on open-source ecosystems.

A developer reviewing code on a dark-themed editor, representing the threat to open-source software supply chains after the coordinated attack on RubyGems in May 2026.
RubyGems, the standard package manager for the Ruby programming language, has temporarily suspended new account registrations following what has been described as a major malicious attack against the registry. The incident, which saw more than 500 harmful packages published in a short window, is the latest in a series of attacks targeting open-source software ecosystems and underscores the growing risk that software supply chains represent for enterprise development teams worldwide.
The attack was first flagged by Maciej Mensfeld, Senior Director of Enterprise Security and Networking at Mend.io, which secures RubyGems. Mensfeld described the incident as a coordinated campaign, noting that hundreds of packages were involved, some targeting the registry's security systems directly and others carrying active exploits. New account signups were suspended immediately as a containment measure, with the RubyGems signup page displaying a notice that registration had been temporarily disabled.
Mend.io confirmed that more than 120 malicious packages were initially pulled from the registry, with that figure ultimately rising to over 500 as the full scope of the campaign became clear. Ruby Central's Marty Haught characterised the activity as a coordinated spam-publishing campaign, limited to newly registered accounts pushing large volumes of junk packages. Bot accounts responsible for the activity have since been blocked and removed from the platform.
RubyGems confirmed that the malicious activity has stopped and that all packages published during the attack have been removed from the registry. However, account signups will remain closed while the platform coordinates with content delivery and security partner Fastly to enable web application firewall protection and tighten rate limiting on account creation. That process is expected to take two to three days.
The incident fits a pattern that security researchers have tracked with increasing concern. Software supply chain attacks targeting open-source ecosystems have risen significantly, with threat actors using automated tools to push compromised or counterfeit packages into widely used registries. In some cases, these packages are designed to steal credentials from developer environments, harvest sensitive configuration data, or serve as entry points into enterprise systems that rely on open-source dependencies.
Mend.io noted that one group known to exploit open-source ecosystems, tracked as TeamPCP, has been observed compromising widely used packages to distribute credential-stealing malware. Google separately reported that credentials stolen from affected developer environments have been monetised through partnerships with ransomware and data theft extortion groups, a detail that places the RubyGems incident within a much broader criminal ecosystem.
For development and security teams across the MENA region, this incident carries direct relevance. Many enterprise applications built on Ruby or Ruby on Rails pull dependencies from RubyGems as part of their build pipelines. A compromised package that reaches production before it is detected can expose sensitive configuration data, introduce backdoors into deployed applications, or create pathways for lateral movement within enterprise environments.
Organisations should audit their current dependency lists against the packages published between the start of the attack window and RubyGems' confirmation that the registry has been cleared. Dependency scanning tools and software composition analysis platforms should be run against any projects that pulled from RubyGems during this period. Development teams working across the Gulf's fast-growing technology sector, where Ruby remains common in fintech, e-commerce and SaaS applications, should treat this as a prompt to review their supply chain security practices more broadly.
The RubyGems incident reinforces a fundamental principle: open-source registries, despite their scale and community oversight, are not inherently secure. The low barrier to publishing packages, combined with the speed at which automated tools can flood a registry, means that even well-established ecosystems require active security controls, not just community vigilance. WAF protection and rate limiting, the measures RubyGems is now implementing, represent a baseline response. More mature defences include package signing, verified publisher programmes and automated behavioural analysis of newly submitted packages before they become publicly available.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.