ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Open Source

SleeperGem abuses RubyGems by shipping malicious gems for extra payloads

Source headline: SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 18 hours ago

Intelligence Summary

A supply chain campaign called SleeperGem has been tied to malicious RubyGems packages. Three rogue gems were published with version ranges that could be pulled during normal Ruby dependency installs. Once fetched, the packages are intended to deliver additional payloads to developer machines. This can lead to unauthorized code execution and compromise of workstations and build environments. Ruby maintainers and developers should verify gem sources, pin dependencies, and review lockfiles for these names and versions.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#supply-chain #malicious-packages #developer-machines #ruby #rubygems
Original reporting The Hacker News SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Open original source