SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
ID: 2863513a-ecec-5d4e-9090-e05b9b00aefd
STIX ID: report--2863513a-ecec-5d4e-9090-e05b9b00aefd
Feed Name: Aikido Security's Blog
A malicious RubyGem named git_credential_manager was published and iteratively developed over hours to act as a dropper: it fetched binaries from a Forgejo host (disabling SSL verification), executed them via shell/PowerShell, and was later wired to run on mere require() calls. The attacker added this gem as a dependency to other packages and appears to have compromised multiple maintainer accounts, including an unrelated fastlane plugin with 574,661 downloads, suggesting a targeted supply-chain campaign aimed at developer machines rather than CI runners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
