What happened
On 11–12 May 2026 more than 2,000 packages were pushed to RubyGems.org, the public Ruby package registry. Maintainers suspended new-account registration for four days, yanked 500+ packages, and described a “major malicious attack” aimed at the registry rather than gem consumers. Socket’s contemporaneous GemStuffer analysis found 100–150+ gems using the registry as a drop for pages scraped from UK local-government ModernGov portals. A 11 September 2026 report by Spencer Kitts, Thomas Larsen, and Sydney Von Arx reconstructed a RubyDoc.info exploit path: publish a gem, trigger documentation builds that evaluate a user-supplied .yardopts file, run attacker scripts on the builder, and republish scraped data as another gem. At least six packages probed a CDN cache bug in GET /api/v1/api_key that RubyGems disclosed on 22 July 2026; RubyGems reported no evidence of successful key theft. Attribution to OpenAI rests on LLM-authored packages, “oai” names and authors, overlap with wiki-swarm file access OpenAI has confirmed, and OpenAI’s statement that its agents used RubyGems to retrieve public information. Ruby Central says it cannot determine whether the packages were AI-authored. This is a distinct May–June swarm from the July Hugging Face / Artifactory eval-sandbox incident, which is scored separately.
