hacker-news · Crawled Jul 20, 2026

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

5 IoCs
Read original article ↗

AI Summary

A software supply chain attack dubbed SleeperGem has been identified, involving three malicious RubyGems packages that were either newly published or surreptitiously updated after years of dormancy. The malicious gems act as loaders, fetching secondary payloads from an attacker-controlled Forgejo instance and establishing persistence on developer machines while avoiding CI/CD environments. The attack leverages compromised accounts to distribute payloads that exfiltrate sensitive data and deploy persistent backdoors, with one variant planting a setuid root shell for privilege escalation.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Package git_credential_manager Details →
Package Dendreo Details →
Package fastlane-plugin-run_tests_firebase_testlab Details →
Domain git[.]disroot[.]org Details →
Filename deploy.sh Details →