Security · 18h ago
SleeperGem Attack Plants Malicious RubyGems to Hijack Developer Machines
Three malicious RubyGems packages, including git_credential_manager and Dendreo, were published to target developer machines in a supply chain attack called SleeperGem. The gems serve additional payloads after installation. Researchers urge developers to audit their dependencies and verify gem integrity.
Meridian48 take
This attack underscores the persistent vulnerability in open-source ecosystems, where a single malicious package can compromise countless downstream projects.
Read the full reporting
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines →
The Hacker News
supply-chain-attackrubygems