SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Overview
Researchers have discovered a new software supply chain attack called SleeperGem, which targets the Ruby ecosystem. Three malicious RubyGems packages, specifically git_credential_manager (versions 2.8.0 to 2.8.3) and Dendreo (versions 1.1.3 and 1.1.4), were published on July 18, 2026. These rogue gems are designed to serve additional malicious payloads, putting developers who use these packages at risk. The attack could lead to unauthorized access and further exploitation of developer machines. It's crucial for developers to avoid these specific versions and to ensure their systems are secure from such threats.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: RubyGems packages: git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) and Dendreo (versions 1.1.3, 1.1.4)
- Action Required: Developers should avoid using the specified versions of the malicious RubyGems packages and ensure their systems are updated and secure.
- Timeline: Newly disclosed
Original Article Summary
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) -
Impact
RubyGems packages: git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) and Dendreo (versions 1.1.3, 1.1.4)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Developers should avoid using the specified versions of the malicious RubyGems packages and ensure their systems are updated and secure.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.