Home / Jul 21, 2026 / Story
0
#8 The Hacker News general July 20, 2026 at 05:15 UTC

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

By [email protected] (The Hacker News)

AI Summary

The SleeperGem supply chain attack published three malicious RubyGems packages to RubyGems.org starting July 18, 2026, including git_credential_manager (versions 2.8.0–2.8.3) and Dendreo (versions 1.1.3–1.1.4), designed to serve additional payloads on developer machines. Targeting a package impersonating git credential management is particularly dangerous given its access to developer authentication tokens.

Relevance score: 78.0/100

# More from July 21