SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.

The rogue gems are listed below –

git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) –

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Ask HN: Has anyone replaced Claude/GPT with a local model for daily coding?

Ask HN: Has anyone replaced Claude/GPT with a local model for daily coding? Source: Hacker News

Digital Printing of Arabic: explaining the problem

Digital Printing of Arabic: explaining the problem Source: Hacker News

In-toto: A framework to secure the integrity of software supply chains

In-toto: A framework to secure the integrity of software supply chains Source: Hacker News