← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 22, 2026 · 21:40via Mend.io Blog

199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ran

Brief

Mend. io’s research team caught this campaign before most of the open source community ever saw it. Continuous monitoring of RubyGems flagged a batch of gems that looked, at a glance, like an ordinary cryptomining squat, and Mend. io reported the full batch to RubyGems for takedown. Every gem was pulled within hours.

Mend. io’s team also pulled two of the samples apart in full, because knowing a campaign exists isn’t the same as knowing how it works. What that deeper look found: real tradecraft wrapped around code that, in both samples examined, doesn’t run at all.

The short version:

199 gems, two accounts, one shared name pool. 181 names are machine-generated nonsense that nobody would ever type into a Gemfile . The other 19 are typosquats of a fully resolved dependency tree, including aws-sdk-core and all four of its direct dependencies.

Read more on Mend.io Blog