
"“We're dealing with a major malicious attack on Ruby Gems right now,” Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. “Signups are paused for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits.”"
"Visitors to RubyGems' sign up page are now greeted with the message: “New account registration has been temporarily disabled.”"
"Mend.io, which secures RubyGems, said it intends to release more details once the incident is contained. It's currently not known who is behind the attack."
"The development comes as software supply chain attacks targeting the open-source ecosystems have been on the rise, with threat actors like TeamPCP compromising widely used packages to distribute credential-stealing malware capable of harvesting sensitive data and allowing the attackers to expand their reach. In a report published Monday, Google said the credentials stolen from affected environments have been monetized through partnerships with ransomware and data theft extortion groups."
RubyGems has temporarily paused new account sign ups following a major malicious attack on Ruby Gems. The sign up page now shows that new account registration is disabled for the time being. Hundreds of packages are involved, with most targeting Mend.io and some carrying exploits. Mend.io, which secures RubyGems, plans to release more details once the incident is contained. The attacker behind the incident is not yet known. The event aligns with rising software supply chain attacks against open-source ecosystems, including cases where threat actors compromise popular packages to distribute credential-stealing malware. Stolen credentials have been monetized through ransomware and data theft extortion partnerships.
Read at The Hacker News
Unable to calculate read time
Collection
[
|
...
]