SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.

The rogue gems are listed below –

git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) –

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

Next Post

World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

Related Posts
Total
0
Share