A reported RubyGems campaign used delayed execution and sandbox checks to keep trojanized libraries quiet until they could launch XMRig and start covert Monero mining.
A cluster of malicious Ruby packages points to a familiar pattern in modern supply-chain abuse: trusted installs can become execution points, and trusted remote access can become a spread path.
A compromised AWS-hosted AI gateway tied to Amazon Bedrock shows how generative AI middleware can become valuable enough to hijack for cryptocurrency mining.