HackerFeeds

CyberSecurity News

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

The Hacker News
· July 20, 2026

AI summary

Cybersecurity researchers have identified a new software supply chain attack called SleeperGem that targets the Ruby ecosystem. The attack involves three malicious RubyGems packages that were published to RubyGems in order to deliver additional payloads. Two of the malicious gems are git_credential_manager, with versions 2.8.0 through 2.8.3, and Dendreo, with versions 1.1.3 and 1.1.4. The git_credential_manager gem was published on July 18, 2026. These rogue gems are part of the SleeperGem attack, which aims to target developer machines. The malicious gems were made available on RubyGems, a package manager for Ruby.

Read the full article at The Hacker Newsthehackernews.com/2026/07/sleepergem-uses-three-malicious.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.