As cited
Copy frozen at (site build).
threat intel
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Researchers disclosed a software supply chain attack called SleeperGem that distributed three malicious RubyGems packages to the Ruby ecosystem. The attack was designed to deliver additional payloads to developer machines through compromised gems including git_credential_manager and Dendreo.
Why it matters: Ruby developers who installed these malicious gems are at risk of compromise, and organizations using these dependencies in their applications face potential code execution on developer machines and in CI/CD pipelines.
- Source published
- First seen by Cybersecurity Tracker