{ads}

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines



July 20, 2026 at 10:45AM

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) -

from The Hacker News https://ift.tt/0Vhsfam

0 Response to "SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines"

Post a Comment

Article Top Ads

Central Ads Article 1

Middle Ads Article 2

Article Bottom Ads