logo

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

ID: 12469815-c447-5ee9-8a90-8e2eb882810a

STIX ID: report--12469815-c447-5ee9-8a90-8e2eb882810a

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: [email protected] (The Hacker News)

...
...

Security researchers uncovered "SleeperGem", a malicious software supply-chain campaign where attackers published rogue RubyGems that load additional payloads from an attacker-controlled Forgejo host, avoid CI environments, drop native daemons, establish persistence (cron and systemd user service), and attempt privilege escalation by planting a setuid root shell; the report also highlights separate abuse of RubyGems as a dead-drop for exfiltrated credentials and other sensitive data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.