logo

GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping

ID: 82dbdfcf-5883-5f41-93a6-3cb9ab3a4875

STIX ID: report--82dbdfcf-5883-5f41-93a6-3cb9ab3a4875

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Ddos

...
...

Socket’s research uncovered “GemStuffer,” a campaign that systematically scrapes council ModernGov portals (examples: Lambeth, Wandsworth, Southwark) and exfiltrates the collected pages by embedding HTTP responses into .gem packages pushed to RubyGems. The actors use Ruby-specific techniques (overriding HOME to a /tmp gem home, strict credential permissions, manual API POSTs, and binary writes to avoid encoding errors) to blend with normal package publishing; mitigations include yanking malicious gems, auditing /tmp gem homes, monitoring ENV['HOME'] mutations, and restricting outbound pushes to rubygems.org.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.