RubyGems Rumble: Malicious Packages Steal Developer Credentials in South Korea! 🚨
Over 60 malicious Ruby gems have been downloaded over 275,000 times, stealing credentials from unsuspecting developers. The gems, targeting South Korean users of popular automation tools, offer fake GUIs and phish for login info. It’s a supply chain attack with a twist—because who said hackers can’t have a sense of humor?

Hot Take:
Looks like South Korean developers using Ruby gems have been caught in a “gem heist” worthy of Ocean’s Eleven! With malicious code masquerading as helpful automation tools, it seems like these coders are now dealing with a ‘Ruby’ red alert instead of a gem of a package!
Key Points:
- Sixty malicious Ruby gems have been downloaded over 275,000 times since March 2023.
- These gems targeted South Korean users, particularly those using automation tools for social media and blogging platforms.
- The gems were published on RubyGems.org under various aliases, making them difficult to trace.
- These gems act as phishing tools to steal credentials using fake GUIs.
- Sixteen of these malicious gems are still available despite being reported to the RubyGems team.
Already a member? Log in here