A cluster of malicious Ruby packages points to a familiar pattern in modern supply-chain abuse: trusted installs can become execution points, and trusted remote access can become a spread path.