Neat Digest  ·  Archive  ·  Open in app ↗

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Score 1.9/10 · 1 sources · July 20, 2026
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have identified a software supply chain attack named SleeperGem targeting the Ruby ecosystem. Three malicious RubyGems packages were published to the official RubyGems repository, designed to compromise developer machines. The attack aims to steal sensitive data, credentials, or deploy further malware. The malicious gems were discovered by security teams monitoring package registries for suspicious activity. The incident highlights ongoing risks in open-source software supply chains, where attackers inject malicious code into widely used libraries. No specific developer or organization has been named as a victim yet, but the potential impact spans any Ruby developer who installed these packages. RubyGems maintainers have been notified and are working to remove the malicious packages.

Global Impact

This attack is a focused supply chain compromise within the Ruby developer ecosystem. Economically, it could lead to credential theft and downstream breaches in companies using Ruby, particularly in web development and DevOps.