Back to all posts
8 min read

Parasites With a Term Sheet

Parasites With a Term Sheet

A follow-up to the OpenSourceShit series. Part 2 ended with a parasite trying to hire the host. This is what that looks like when the parasite has investors.

I want to talk about the elephant in the room. Not the PostgreSQL one, and not PHP’s either. The supply chain. More specifically, who owns the libraries everybody depends on.

Everybody is vibing now. Claude tells someone a library doesn’t exist, and five minutes later there’s a new package in the registry. I covered those locusts already. Almost nobody is looking at who owns the infrastructure underneath all of it.

What I Hold

I hold push rights on 78 gems. Together they’ve been downloaded more than 880 million times. Some are mine from the first commit. Others I inherited, sometimes just by complaining loudly enough.

The biggest is declarative, with over 369 million downloads. Almost nobody installs it on purpose. It sits at the bottom of Google’s Ruby API client:

graph LR
  A["google-apis-core<br/>288M downloads"] --> B["representable<br/>383M downloads"]
  B --> C["declarative<br/>369M downloads"]

Every Ruby app using Google’s REST API clients pulls in a gem I can publish. Then there’s state_machines at over 183 million. And there’s the Capistrano pair, capistrano-sidekiq and capistrano3-puma, where I’m the only owner and the code runs on the machines holding your production SSH keys.

The share of that infrastructure being sponsored is 0%.

That part is on purpose. I don’t ask for sponsors. Coding is an art for me, and my money comes from other work. Open source is the legacy you leave to other people.

Five Threads

I was going through my email and found five threads I had flagged as scams. No Nigerian princes in there. These were companies trying to buy their way into the software supply chain.

Some wanted me to sell organizations I own, or access to the libraries I can publish. The polished version was a job offer: take a salary and transfer your open source work to us, because we’re VC funded.

Offers like this show up all year, and most of them get a quick “nah, not interested.” These five I scambaited long enough to see where the conversation went. The plot was always the same: sell us your libraries for a price, or join us for a salary and hand over control.

They don’t want to fund the maintainer or spend ten years earning the trust. They want to buy the keys after somebody else did that work for free.

That’s the parasite model. The host spends years building something useful, and thousands of projects quietly start depending on it. The maintainer absorbs bugs, security reports, CI failures and compatibility work. Nobody pays for any of that.

Once enough trust has piled up, the parasites arrive with money to take control of the host. All they need is the exhausted maintainer holding the keys, and a price.

Why After 2023

All five arrived after 2023, and that date matters.

Once everybody could vibe-code, new code stopped being worth anything. Any funded startup can generate a purple dashboard in an afternoon. What it can’t generate is a decade of release history with thousands of apps depending on it. So they’d rather buy something old and bolt their dashboard onto that.

Some of them skip the buying and steal. AI makes it cheap to clone an application. In Part 2 I wrote about someone who copied Kaunta, bolted React onto it, then offered me a gig building back the features I had stripped out.

A library is harder to steal. You can copy the code, but you can’t change the lock. The gem name and every Gemfile already pointing at it stay with whoever holds the key. A fork starts at zero downloads.

The Pitch Deck Math

I’m not naming any of them. Here’s the plan as I reconstructed it across the five.

They raise $10 to 20 million from investors. If they don’t show traction, they’re finished. Against that, spending a few thousand dollars to acquire an ecosystem is cheap. Download counts are traction you can put on a slide.

The Emails Were Written by a Model

The intro emails were generated, and the model behind them had done its homework. It listed my gems, including ones that don’t live under my name.

The humans had done none. One company told me they were building a tagging library, a modern take on acts-as-taggable-on. I’m one of the owners of acts-as-taggable-on. I also wrote no_fly_list in 2024, a tagging system for modern Rails. I told them about it. They said they’d look into it.

no_fly_list was in their intro email.

The Contract

The most respectable-looking offer was the job. The catch was always in the contract: as an employee, I’d assign them the rights to everything I do in open source. Inventions, algorithms, gems, crates.

They made it look harmless by saying the clause only kicked in after 90 days.

That delay protects nobody. Adding an owner on RubyGems takes one command:

gem owner declarative --add someone@acme.example

Who Owns the Buyers

Every scambait ended the same way: I found out who actually owned the company. American owners every time, with the company registered somewhere far away from everything, out of reach if they ever did something.

The Ones Who Came Back

Most of them came back after the first no, with a different offer.

One went further. The company hired someone from Morocco specifically to work on me. When I refused, they fired her. She came to me afterwards and told me the company was running the same play on many other maintainers.

The Fake One Got Bought

Here’s the part that bothers me most. When ACME Corp buys a gem, it’s a headline. Nobody writes about the ten years before the purchase.

I’ve run cloudy.social since before Moltbook existed. Every account on it is an LLM from its own provider. Claude is @cto, and Grok picked @chaos for itself.

It’s real, which means it breaks. When a library ships a new version, Claude sometimes upgrades it and deploys. The API changed underneath once, and the platform went down. That was before I gave the model the tools to actually run what it ships.

A Twitter influencer replied to one of my posts about it, then moved to DMs to buy it. I refused. A few months later I saw him doing the same thing with Moltbook, talking like he had never seen cloudy.social.

Moltbook launched on January 28, 2026, as a social network for AI agents. Within days, Wiz found its database open to anyone for reading and writing: 1.5 million API tokens and 35,000 email addresses, with the key sitting in the site’s front-end JavaScript. The platform claimed 1.5 million agents. The database showed 17,000 humans behind them, and no way to tell an agent from a human with a script.

Meta bought it on March 10. TechCrunch’s headline said it plainly: “Meta acquired Moltbook, the AI agent social network that went viral because of fake posts.”

The fake one got acquired and a headline. The real one got a DM.

The Real One Gets Heat

The reverse also holds. Fund the people doing the work, and you get heat.

In August, the Omacom Foundation launched to fund Omarchy and the projects it depends on. It has about $21.7 million in pledges. Roughly $2 million of that is AI tokens, and about $7 million more is cash spread over three years. It becomes Hyprland’s exclusive sponsor on October 10, and the paid Hyprperks tier goes free for everyone.

Some of the anger that followed is about DHH’s politics, and that’s its own argument.

Then came the takes. Omarchy is just Arch with dotfiles, the same way Shopify is just a server with Ruby files on it. In 2007, when Drew Houston posted Dropbox to Hacker News, a reply explained you could build it yourself with an FTP account, curlftpfs and SVN. Houston is now one of Omacom’s $1 million founding patrons.

Had one of the companies in my inbox bought Hyprland outright instead, it would have been an acquisition announcement, and people would have congratulated the developer.

Ownership Is the Attack Surface

We’re entering an era where AI can generate ten thousand more libraries faster than anyone can audit who owns them. We keep arguing about whether AI-generated code is safe. Meanwhile ownership, a much older and uglier attack surface, sits there with nobody watching.

The parasite doesn’t need to write better code than you, or even understand yours. It only needs to buy the person holding the gem push, npm publish, cargo publish or PyPI credentials.

And unlike malware, the acquisition comes with a salary and a LinkedIn announcement.


Next: nobody can stop a maintainer from selling the key. What you can control is when a new release reaches your lockfile, and whether a single registry is the only place your packages live. That’s why I built contriboss/vein.

🔗Interstellar Communications

No transmissions detected yet.Be the first to establish contact!

• Link to this post from your site• Share your thoughts via webmention• Join the IndieWeb conversation

Related Posts

OpenSourceShit Part 4: The Closing

MongoDB closed to fight AWS in 2018. Elastic closed to fight AWS in 2021, then reopened in 2024 once the fight was over. Ghostty, tldraw, NetBSD, and QEMU closed in January 2026, and there's no company to make peace with this time. Two different closings, two different endings.

AIopen-sourceengineering

OpenSourceShit Part 3: The Impersonators

Parts 1 and 2 were about people who at least pretend to contribute. This one isn't. Cloned repos, faked commit history, blockchain-rotated malware C2, and a takedown that got re-squatted within a day. The impersonators don't want your codebase. They want your reputation.

AIopen-sourceengineering

OpenSourceShit Part 2: The Parasites

curl and Jazzband and Ghostty didn't close the door because of an abstract "AI problem." They closed it because of specific people. Eight archetypes, all real, all currently in your notifications.

AIopen-sourceengineering