would you have to go out of your way to find a malicious gem though? Its not like any of the popular gems would try to overwrite files, right?
After this got uncovered, Duo published a blog post where they scanned for and found several others malicious packages:
https://duo.com/blog/hunting-malicious-npm-packages
The last one they talk about worms itself by adding itself to any packages authored on the computer it's installed on.
These issues are not unique to npm.
Granted that was just data collection, but the outcome could be incredibly worse if a combo of popular but bad code and a little bit of money.
The problem here is that you don't even have to get directly attacked to be affected.