GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
ID: 08827e49-76e0-5836-8869-71b74da5c852
STIX ID: report--08827e49-76e0-5836-8869-71b74da5c852
Feed Name: The Hacker News
Researchers identified a campaign dubbed GemStuffer that abused the RubyGems registry to publish over 150 packages containing scraped content from UK local government portals (meeting calendars, agendas, PDFs, contact details, RSS feeds). The malicious gems either built and pushed archives using embedded credentials or uploaded them directly via the RubyGems API; once published, the scraped data can be retrieved with a simple 'gem fetch'. Socket researchers assess this is registry abuse for bulk archival or data staging rather than a mass-scale malware distribution, though it raises supply-chain and government-infrastructure pivot concerns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
