RubyGems has introduced an opt-in cooldown feature in RubyGems 4.0.13 and Bundler 4.0.13 that delays installation of newly published gem versions to reduce exposure to malicious releases. The control lets developers require a gem version to be public for a configurable number of days before Bundler will resolve it, using per-version created_at timestamps from RubyGems.org’s v2 compact index. The feature is disabled by default, can be bypassed with:
bundle install --cooldown 0
The release comes as software supply-chain defenders respond to fast-moving package compromises, including a backdoored @cap-js/openapi 1.4.1 package on npm. Guidance for affected environments says any host with that version in its dependency graph should be treated as untrusted, upgraded to 1.4.2 or later, and followed by recycling developer sessions, execution nodes, and CI/CD containers, plus rotating exposed secrets such as AWS keys, GitHub tokens, database credentials, and npm tokens. RubyGems said the cooldown mechanism complements broader ecosystem protections including mandatory 2FA, trusted publishing, compromised-password checks, push-time validation, and AI-assisted vulnerability scanning.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
A remediation notice stated that npm package @cap-js/openapi version 1.4.1 contained backdoored code and directed organizations to upgrade to version 1.4.2 or later. The notice also advised treating affected hosts as untrusted and rotating sensitive credentials.
On the RubyGems blog, the project announced a new opt-in Bundler cooldown feature that delays installation of newly published gem versions so they can be vetted before use.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
socket.dev
Open sourcecvereports.com
Open sourceblog.rubygems.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.