SleeperGem is a threat campaign tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed July 19, 2026; most recent activity July 20, 2026.
A supply chain attack named SleeperGem has been identified targeting the RubyGems ecosystem, exploiting dormant maintainer accounts to publish a malicious gem called git_credential_manager. This gem, which has already…