SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have identified a software supply chain attack named SleeperGem targeting the Ruby ecosystem. Three malicious RubyGems packages were published to the official RubyGems repository, designed to compromise developer machines. The attack aims to steal sensitive data, credentials, or deploy further malware. The malicious gems were discovered by security teams monitoring package registries for suspicious activity. The incident highlights ongoing risks in open-source software supply chains, where attackers inject malicious code into widely used libraries. No specific developer or organization has been named as a victim yet, but the potential impact spans any Ruby developer who installed these packages. RubyGems maintainers have been notified and are working to remove the malicious packages.
Global Impact
This attack is a focused supply chain compromise within the Ruby developer ecosystem. Economically, it could lead to credential theft and downstream breaches in companies using Ruby, particularly in web development and DevOps.