RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded

May 12, 2026

RubyGems, the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a “major malicious attack.”
“We’re dealing with a major malicious attack on Ruby Gems right now,” Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. “Signups are paused for the time being.

Get Free Report & Network Analysis

Please check your email for the free report.