SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.

The rogue gems are listed below –

git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) –

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

OpenAI: Migrating to HTTPX2

OpenAI: Migrating to HTTPX2 Source: Hacker News

The Reversal Curse: LLMs trained on “A is B” fail to learn “B is A”

The Reversal Curse: LLMs trained on “A is B” fail to learn “B is A” Source: Hacker News

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified