Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

PFAS monitoring permanently detects chemicals in all rain and snow samples across the Great Lakes

AI-informed integration of electric vehicles charging infrastructure for resilient distribution grids

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » GemStuffer exploits over 150 RubyGems to leak scraped UK council portal data
Identity

GemStuffer exploits over 150 RubyGems to leak scraped UK council portal data

By May 13, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 13, 2026Software supply chain/data breach

Leaked RubyGems

Cybersecurity researchers are warning people of a new campaign called GemStuffer. This campaign targets the RubyGems repository, which contains over 150 gems, and uses the registry as a data exfiltration channel rather than malware distribution.

“The package does not appear to be designed to compromise large-scale developers,” Socket said. “Many have little or no download activity, and their payloads are repetitive, noisy, and unusually self-contained.”

“Instead, the script retrieves pages from UK local government democratic services portals, packages the collected responses into valid .gem archives, and publishes those gems to RubyGems using a hardcoded API key.”

The development comes after RubyGems temporarily disabled new account registrations following what was described as a large-scale malicious attack. It’s not clear whether the two activities are related, but the application security firm said GemStuffer falls into the “same pattern of exploitation” of using newly created packages with junk names to host scraped data.

Broadly speaking, the campaign exploits RubyGems as a place to stage scraped council content. This is done by taking the hard-coded UK Parliament Portal URL, packaging the HTTP response into valid .gem archives, and publishing those archives to RubyGems using embedded registry credentials.

In some cases, payloads embedded within gems create a temporary RubyGems credential environment under “/tmp”, override the HOME environment variant to build the gem locally, and push it to RubyGems using the Gem command-line interface (CLI), rather than relying on existing RubyGems credentials on the target machine.

Other variants of the malicious gem have been found to bypass the CLI component and upload archives directly to the RubyGems API via HTTP POST requests. Once a new gem is published, all an attacker needs to do is run a “gem fetch” command with the gem’s name and version to access the scraped data.

This novel scraping campaign was found to target the public-facing ModernGov portal used by Lambeth, Wandsworth and Southwark, with the aim of collecting committee meeting calendars, agenda lists, linked PDF documents, executive contact information, and RSS feed content. It’s not clear what exactly the end goal is, since the information appears to be publicly accessible anyway.

Socket assessed that the systematic bulk collection and archiving of this data may allow attackers to use “access to the Congressional Portal as a linchpin to prove their capabilities against government infrastructure.”

“It could be registry spam, a proof-of-concept worm, an automated scraper that exploits RubyGems as a storage layer, or a deliberate test of package registry abuse,” Socket said. “But the mechanics are intentional: repeated gem generation, version increments, hard-coded RubyGems credentials, direct registry pushes, and scraped data embedded within package archives.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMacquarie University advances a new era of bioinnovation
Next Article Ensuring diversity in the age of AI natives

Related Posts

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

May 15, 2026

CISA adds Cisco SD-WAN CVE-2026-20182 to KEV after administrator access exploit

May 15, 2026

Cisco Catalyst SD-WAN Controller Authentication Bypass Is Actively Abused to Gain Administrative Access

May 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

PFAS monitoring permanently detects chemicals in all rain and snow samples across the Great Lakes

AI-informed integration of electric vehicles charging infrastructure for resilient distribution grids

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

CISA adds Cisco SD-WAN CVE-2026-20182 to KEV after administrator access exploit

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.