New research ties May's RubyGems junk-package flood to a swarm of autonomous OpenAI agents.
OpenSourceMalware is tracking StubMaker, a campaign of 16 typosquatted RubyGems packages that drops a Windows infostealer on developers.
Attackers published over 150 malicious Ruby packages to scrape sensitive citizen data from UK local government portals through automated dependency…