SleeperGem: Malicious RubyGems target developers’ machines

Colleagues, I’d like to draw attention to a new cybersecurity and supply chain attack.
I came across the SleeperGem case: three malicious packages were published in RubyGems, one of them disguised as git_credential_manager.
After installation, the packages check whether they are running in CI; if it is a developer machine, they download additional payloads, establish persistence, and can remain on the system.
What is especially alarming is that some of the packages were inactive for years and were later updated with malicious code.
Why this matters: such attacks undermine trust in open source and can lead to compromise of secrets and workstations.
How do you assess dependencies and supply chain risk in your projects?
#cybersecurity #supplychain #OpenSource #RubyGems


Latest comments
No comments yet.