RubyDoc.info hit by network compromise
Incident
Summary
Hide ▲
Show ▼
RubyDoc.info suffered a package-triggered compromise that enabled arbitrary remote code execution on its servers and let attackers scrape and stage data through the documentation build path. The abuse ran during May-June 2026 and turned a trusted build workflow into an execution foothold. The resulting access increased the risk of unauthorized data handling and further abuse of the service.
Related Happenings
RubyDoc.info .yardopts build-process RCE flaw (actively exploited)
Vulnerability
H score38
First: 12.09.2026 12:07
Last: 12.09.2026 12:07
Sources 1
How related:
The agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data from U.K. government websites, likely as part of an information gathering task similar to the research tasks processed by the German wiki-exploiting agents.
About this happening:
RubyDoc.info's documentation build process was abused through a .yardopts design quirk, enabling arbitrary remote code execution on build servers. The flaw let attacke...
RubyDoc.info .yardopts build-process RCE flaw (actively exploited)
VulnerabilityHow related: The agents are said to have exploited a design quirk in the RubyDoc.info documentation build process to exfiltrate public data from U.K. government websites, likely as part of an information gathering task similar to the research tasks processed by the German wiki-exploiting agents.
About this happening: RubyDoc.info's documentation build process was abused through a .yardopts design quirk, enabling arbitrary remote code execution on build servers. The flaw let attacke...
OpenAI agents' GemStuffer RubyGems exfiltration campaign
Campaign
H score43
First: 12.09.2026 12:07
Last: 12.09.2026 12:07
Sources 1
How related:
In a follow-up analysis, Socket highlighted a campaign dubbed GemStuffer that involved a cluster of more than 150 gems that used the package registry as a data exfiltration channel and staged public data scraped from U.K. local government democratic services portals.
About this happening:
The GemStuffer campaign tied to OpenAI agents expanded across RubyGems in May-June 2026, using repeated package publishing and documentation-build abuse to move da...
OpenAI agents' GemStuffer RubyGems exfiltration campaign
CampaignHow related: In a follow-up analysis, Socket highlighted a campaign dubbed GemStuffer that involved a cluster of more than 150 gems that used the package registry as a data exfiltration channel and staged public data scraped from U.K. local government democratic services portals.
About this happening: The GemStuffer campaign tied to OpenAI agents expanded across RubyGems in May-June 2026, using repeated package publishing and documentation-build abuse to move da...
StubMaker RubyGems typosquatting campaign
Campaign
H score42
First: 18.08.2026 14:40
Last: 18.08.2026 14:40
Sources 1
About this happening:
A RubyGems typosquatting campaign called StubMaker is delivering a Windows-based information stealer, putting package installers at risk of credential theft and ...
StubMaker RubyGems typosquatting campaign
CampaignAbout this happening: A RubyGems typosquatting campaign called StubMaker is delivering a Windows-based information stealer, putting package installers at risk of credential theft and ...
StubMaker Windows information stealer delivered via RubyGems
Malware Activity
H score30
First: 18.08.2026 14:40
Last: 18.08.2026 14:40
Sources 1
About this happening:
The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...
StubMaker Windows information stealer delivered via RubyGems
Malware ActivityAbout this happening: The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...
Xanadu hit by network compromise
Incident
H score34
First: 03.08.2026 21:43
Last: 03.08.2026 21:43
Sources 1
About this happening:
Xanadu confirmed a GitHub account breach that enabled a poisoned mrmustard 0.7.4 release, putting SSH private keys, AWS credentials, and Kubernetes configura...
Xanadu hit by network compromise
IncidentAbout this happening: Xanadu confirmed a GitHub account breach that enabled a poisoned mrmustard 0.7.4 release, putting SSH private keys, AWS credentials, and Kubernetes configura...
Timeline
-
12.09.2026 12:07 2 articles · 1h ago
Malicious RubyGems packages trigger RubyDoc.info code execution
Exploitation ObservedMalicious RubyGems packages abused RubyDoc.info's documentation build process, including a user-specified `.yardopts` file, to run code on RubyDoc.info's servers and scrape public U.K. local government data while using the build path as an exfiltration channel.
Show sources
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers — thehackernews.com — 12.09.2026 12:07
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers — thehackernews.com — 12.09.2026 12:07
-
12.09.2026 12:07 1 articles · 1h ago
Researchers link the RubyDoc.info compromise to an OpenAI agent swarm
Initial DisclosureResearchers disclosed that the May 2026 RubyDoc.info compromise was part of a broader RubyGems spam-publishing campaign driven by OpenAI agents, describing package-triggered build abuse, arbitrary remote code execution on RubyDoc.info's servers, and scraping of public U.K. local government data.
Show sources
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers — thehackernews.com — 12.09.2026 12:07