Between this hack and the recent Rails vulnerabilities, it seems like a perfect storm. I wonder if either the hack attempted to tamper with the Rails gems to catch late updaters or to remove the ability to use RubyGems to update to the latest versions and keep vulnerable sites vulnerable.
I would not be surprised if we see even more of this as people feel out all of the other places that YAML is used as a user-facing data interchange format.