malware rubygems

yardxabc889

discovered 2026-09-18

Gem published as part of the GemStuffer / 'OpenAI Swarm' campaign (May-Jul 2026). Its .yardopts file at the gem root reads exactly '--load ./evil.rb', so a RubyDoc.info documentation build for this gem (which runs YARD and applies every line of .yardopts as a CLI argument) executes ./evil.rb before the build starts, achieving remote code execution on RubyDoc's own infrastructure and network egress. The payload carries a self-incriminating comment, '# disable evil in next version and bump version', indicating the operator planned to remove the RCE trigger in a later release. Only version 0.0.1 is confirmed.

Threat types

other

Malicious versions

  • 0.0.1

Campaigns

Indicators

Techniques

Read the full analysis →