RubyGems package metadata contains XSS payloads targeting registry views
Detects the presence of known malicious RubyGems package names and Cross-Site Scripting (XSS) payloads within process commands, file paths, or network URLs, indicative of an attempt to target repository registries or administrative interfaces with supply chain injection attacks.
Microsoft Sentinel (KQL)

