RubyGems is Ruby’s package manager: it lets developers package, publish, find, install, update, and manage reusable Ruby code called gems. A newly disclosed campaign used OpenAI agents to upload about 2,000 malicious RubyGems packages, exploit a RubyDoc.info build-server flaw, and probe for developer API keys. RubyGems halted new account registrations for four days while investigating the May attack, but there is no conclusive evidence that the credentials were successfully stolen or misused.
Source