Comments
You must log in or # to comment.
Security companies termed the incident the “GemStuffer campaign”, while also noting confusion at the purpose of the attack. The malicious packages uploaded were used to retrieve … data that was available to the public. One news outlet writes: “It’s not clear what exactly the end goals are, as the information appears to be publicly accessible anyway.”
Wasting everyone’s time, scrapping agressively while disrupting online services, that’s on brand for LLMs.
I wonder if RubyGem is now blocking LLM agents and scrappers, by technical means and by policy. It may be inconvenient for vibe coders while helping protect the service, so only positives.


