SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
A supply chain attack involving three malicious RubyGems packages is targeting developer systems to establish persistent backdoors.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A campaign identified as SleeperGem is targeting developer machines by compromising existing RubyGems packages. The malicious activity involves the use of three packages—git_credential_manager, Dendreo, and fastlane—to deploy persistent backdoors. Additional reports suggest a related threat involving OTTERCOOKIE malware concealed within SVG images.
Coverage from Cyberpress.org, Aikido Security, StepSecurity, and The Hacker News emphasizes the targeting of dormant maintainer accounts. These reports highlight how the supply chain attack leverages trusted package infrastructure to infiltrate development environments. Attention remains on the maintenance status of affected RubyGems packages and the potential for further malware distribution.
Coverage does not yet specify the full scope of system impacts or recovery timelines for compromised repositories.
Synthesized by headlinez.news from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 4h ago.
Quick answers
What is SleeperGem?
SleeperGem is a supply chain attack that utilizes malicious RubyGems packages to target developer machines and install persistent backdoors.
Which packages are involved?
According to reports, the attack involves the git_credential_manager, Dendreo, and fastlane RubyGems packages.
Is other malware related to this campaign?
Cyberpress.org reports that North Korean hackers are also utilizing OTTERCOOKIE malware hidden in SVG images to backdoor developers.
Coverage (4)
- North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers cyberpress.org · 1d ago
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts Aikido Security · 1d ago
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor StepSecurity · 1d ago
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines The Hacker News · 1d ago
Topics
Related trends
Lockscreen bug can let hackers bypass security via Gemini AI on Android phone; Google to roll out security fix soon
A security vulnerability in the Android Gemini AI integration allows unauthorized users to send text messages while a device is locked.
RedHook Android malware can quietly hijack your phone
The RedHook Android malware has resurfaced with upgraded capabilities, posing a significant security threat to mobile users across Southeast Asia.
Microsoft rushes out Windows fix for Dell's hot and bothered PCs
Microsoft has deployed an emergency Windows 11 update to resolve critical reliability and overheating issues impacting specific Dell laptop models.
LG’s monitors come with an unwanted addition for Windows: McAfee pop-up ads
LG monitor users report the automatic, unsolicited installation of McAfee software on Windows PCs.
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
A vulnerability identified as 'WP2Shell' is facilitating remote takeovers of WordPress websites.
Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense
Hugging Face reports using a Chinese AI model to repel an autonomous cyberattack after U.S. model safety restrictions prevented a defensive response.