Skip to content
The Nexus
SECURITYJul 20 · 05:15 UTCTHE HACKER NEWS[email protected] (The Hacker News)

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers identified a new software supply chain attack named SleeperGem targeting the Ruby ecosystem through three malicious RubyGems packages. The attack involves gems like git_credential_manager (versions 2.8.0-2.8.3) and Dendreo (versions 1.1.3, 1.1.4), designed to deliver additional payloads to developer machines.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting