RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security Changes
A fresh set of 60 malicious packages has been uncovered targeting
the RubyGems ecosystem by posing as seemingly innocuous automation
tools for social media, blogging, or messaging services to steal
credentials from unsuspecting users. The activity is assessed to be
active since at least March 2023, according to the software supply
chain security company Socket. Cumulatively, the gems have been
Read more https://thehackernews.com/2025/08/rubygems-pypi-hit-by-malicious-packages.html