#8
The Hacker News
general
July 20, 2026 at 05:15 UTC
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
By [email protected] (The Hacker News)
AI Summary
The SleeperGem supply chain attack published three malicious RubyGems packages to RubyGems.org starting July 18, 2026, including git_credential_manager (versions 2.8.0–2.8.3) and Dendreo (versions 1.1.3–1.1.4), designed to serve additional payloads on developer machines. Targeting a package impersonating git credential management is particularly dangerous given its access to developer authentication tokens.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →