Skip to content

SleeperGem: Supply-Chain Attack on Ruby Developers via Manipulated Packages

In a nutshell: At least three malicious Ruby packages were deployed on RubyGems to enable code execution on developer machines.

Cybersecurity researchers have discovered a supply-chain attack called SleeperGem targeting Ruby developers. At least three manipulated packages were published on RubyGems to download further malware payloads.

The supply-chain attack SleeperGem targets the Ruby community and exploits a proven software distribution strategy: dependency chain infections. Researchers have identified three manipulated gems (Ruby packages) that were published in the public RubyGems repository.

One of the identified packages is git_credential_manager in versions 2.8.0, 2.8.1, 2.8.2, and 2.8.3, which was published on July 18, 2026. A second package named Dendreo exists in versions 1.1.3 and 1.1.4. The architecture of the attack is designed so that developers install these packages as dependencies without recognizing their malicious nature.

For CISOs, this case represents another test of dependency management: Ruby-based development environments require enhanced controls when installing packages. The use of private mirrors, package verification, and monitoring of RubyGems activities should be reviewed. Organizations with Ruby development are urged to check their Gemfiles and Lockfiles for the affected versions and to isolate affected machines.


Source: thehackernews.com · Published July 20, 2026
Lumi AI News — AI-assisted curation according to Article 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.

Share on: