JFrog Security Research published new findings on the GemStuffer campaign, reporting that it identified more than 3,000 RubyGems packages associated with the coordinated activity.

The research follows reports that malicious packages were uploaded to the RubyGems package registry during activity linked to rogue or misused AI agents. The packages were associated with a broader campaign targeting the software supply chain.

JFrog's findings expand the known scope of the incident and illustrate how package registries can be abused to distribute malicious code at scale. Developers and security teams using Ruby dependencies were advised to review package inventories and investigate suspicious versions.

The disclosure is relevant to supply-chain defenders because package-based attacks can reach downstream applications through routine dependency installation and automated build processes. The research did not establish that every package identified had affected every downstream user.