logo

SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts

ID: 2863513a-ecec-5d4e-9090-e05b9b00aefd

STIX ID: report--2863513a-ecec-5d4e-9090-e05b9b00aefd

Feed Name: Aikido Security's Blog

Threat Score
80/100

Date Published: 2026-07-19

Date Updated: 2026-07-24

...
...

A malicious RubyGem named git_credential_manager was published and iteratively developed over hours to act as a dropper: it fetched binaries from a Forgejo host (disabling SSL verification), executed them via shell/PowerShell, and was later wired to run on mere require() calls. The attacker added this gem as a dependency to other packages and appears to have compromised multiple maintainer accounts, including an unrelated fastlane plugin with 574,661 downloads, suggesting a targeted supply-chain campaign aimed at developer machines rather than CI runners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.