SleeperGem: Malicious RubyGems Package Targets Developer Environments

SleeperGem: Malicious RubyGems Package Targets Developer Environments

First seen 20 Jul 2026, 05:15 UTC Aikido.DevTipranksFeeds.Feedburner 83% similarity 67.5

Article Content

Browse articles
ThreatCluster

A supply chain attack named SleeperGem has been identified targeting the RubyGems ecosystem, exploiting dormant maintainer accounts to publish a malicious gem called git_credential_manager. This gem, which has already been downloaded over 574,000 times, retrieves binaries from a self-hosted git server with SSL verification disabled and executes them on developer machines. The attack specifically avoids continuous integration environments, indicating a focus on compromising developer endpoints. The malicious gem was designed to spread by being added as a dependency to other packages, amplifying its reach. The incident raises significant concerns about trust in open source software distribution and the systemic risks posed by dependency compromises. Security researchers are urging developers to be vigilant and review their dependencies for potential threats.

Key Points: • A supply chain attack named SleeperGem targets RubyGems with a malicious gem. • The malicious gem has over 574,000 downloads and executes binaries with SSL verification disabled. • The attack specifically avoids CI environments, focusing on developer machines.

ThreatCluster AI

Timeline

2026-07-19
Malicious gem discovered
A suspicious package named git_credential_manager was found in the RubyGems triage queue, leading to further investigation.
Aikido.Dev
2026-07-19
Malicious gem published
The git_credential_manager gem was published in four versions, with the first version functioning as a dropper for malicious binaries.
Aikido.Dev
2026-07-19
Attack method detailed
The gem was found to bypass CI environments and execute downloaded binaries directly on developer endpoints.
Tipranks
2026-07-19
Dependency spread confirmed
The malicious gem was added as a dependency to other existing packages, allowing it to spread further.
Aikido.Dev

Community

Browse all →