TUESDAY, JULY 21, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 3h ago

Ruby's Bundler Cooldown Feature Mitigated SleeperGem Attack 45 Days Before Exploit

By Meridian48 News Desk · Summarised from DEV Community ·

Bundler 4.0.13 introduced a cooldown feature on June 3, 2026, that delays new gem installations to prevent supply chain attacks. On July 19, attackers compromised three Ruby gems, including one impersonating Microsoft's Git Credential Manager, but the cooldown limited the blast radius. The malicious payload targeted developer machines, dropping backdoors via native binaries, but downloads of the malicious versions were minimal and yanked.

Meridian48 take
The story is less about the attack's scale—most reported download numbers are misleading—and more about how proactive platform defenses can neutralize threats before they spread.
Read the full reporting
Ruby Shipped the Fix for SleeperGem 45 Days Before It Happened →
DEV Community
supply-chain-attackruby-security
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan