SleeperGem: Three Malicious RubyGems Exploit Supply Chain to Target Developer Machines
Cybersecurity researchers identified the SleeperGem supply chain attack, leveraging three malicious RubyGems to deploy payloads that establish persistence on developer machines while evading CI environments. The attack exploits dormant gems and dependencies to spread, with affected users advised to remove malicious components and rotate credentials.
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) -
*** END OF TRANSMISSION ***