CYBER● ELEVATEDJul 20 · Jul 20, 2026, 5:15 AM
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
The Hacker News
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) -
GlobeAlert aggregates and classifies open sources; the story above belongs to its publisher. Summaries are machine-generated from the source text.
More in Cyber
CYBERnow[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIDark ReadingCYBERnow[Virtual Event] Building a Secure AI Strategy for the EnterpriseDark ReadingCYBER2h agoUS seizes over $560,000 in cryptocurrency donations for HamasClarínCYBER3h agoOld, Unpatched Flaws Give Attackers Access to Philippines Nuclear AgencyDark Reading