CyberSecurity News
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
AI summary
Cybersecurity researchers have identified a new software supply chain attack called SleeperGem that targets the Ruby ecosystem. The attack involves three malicious RubyGems packages that were published to RubyGems in order to deliver additional payloads. Two of the malicious gems are git_credential_manager, with versions 2.8.0 through 2.8.3, and Dendreo, with versions 1.1.3 and 1.1.4. The git_credential_manager gem was published on July 18, 2026. These rogue gems are part of the SleeperGem attack, which aims to target developer machines. The malicious gems were made available on RubyGems, a package manager for Ruby.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

