GemStuffer linked 3,022 RubyGems packages to an operation abusing documentation systems to run code and steal credentials.