SleeperGem: RubyGems Supply Chain Attack Targets Dormant Maintainer Accounts (Campaign)
ID: 6a8b72d3-14e6-5048-bbb2-c38b6e607efe
STIX ID: report--6a8b72d3-14e6-5048-bbb2-c38b6e607efe
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-07-19
Date Updated: 2026-07-26
Author: [email protected] (Wiz Threat Research)
On July 18–19, 2026, attacker(s) compromised at least two dormant RubyGems maintainer accounts to publish malicious versions of the git_credential_manager gem that download binaries from a public Forgejo instance, disable SSL verification, and execute payloads via PowerShell or /bin/sh. The malware checks roughly 30 CI environment variables to avoid build servers and target developer laptops, was refined across four versions in a 9-hour window, and was propagated by adding the malicious gem as a dependency to the dendreo gem; version 2.8.3 triggers automatically on require, requiring no explicit installation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
