Back to all news
Security

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

The Hacker News·July 20, 2026·1 min read
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem. Three malicious gems were published to RubyGems with the goal of serving additional payloads. The rogue gems include git_credential_manager and Dendreo, published on July 18, 2026.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store