logo

SleeperGem: RubyGems Supply Chain Attack Targets Dormant Maintainer Accounts (Campaign)

ID: 6a8b72d3-14e6-5048-bbb2-c38b6e607efe

STIX ID: report--6a8b72d3-14e6-5048-bbb2-c38b6e607efe

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2026-07-19

Date Updated: 2026-07-26

Author: [email protected] (Wiz Threat Research)

...
...

On July 18–19, 2026, attacker(s) compromised at least two dormant RubyGems maintainer accounts to publish malicious versions of the git_credential_manager gem that download binaries from a public Forgejo instance, disable SSL verification, and execute payloads via PowerShell or /bin/sh. The malware checks roughly 30 CI environment variables to avoid build servers and target developer laptops, was refined across four versions in a 9-hour window, and was propagated by adding the malicious gem as a dependency to the dendreo gem; version 2.8.3 triggers automatically on require, requiring no explicit installation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.