The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity researchers have identified a software supply chain attack called SleeperGem, involving three malicious RubyGems packages that install persistence mechanisms on developer machines.
- One of the packages impersonates Microsoft's official Git Credential Manager, while the other two were dormant for years before receiving malicious updates.
- The malware checks for CI environment variables to avoid build systems and targets developer machines, where it drops a daemon, establishes persistence, and can escalate to root access.
- Researchers advise users who installed the affected gems to treat their machines and secrets as compromised, remove the malicious files, and rotate credentials.
What to watch next
- Any further malicious packages linked to the compromised maintainer accounts, including "LR-DEV" and "pinkroom".
- Whether RubyGems takes action such as removing the malicious gems or pausing sign-ups again.
- Additional details on the attacker-controlled Forgejo host and any second-stage payloads identified.
Coverage1
1 report
English national1
All filed from India
Named United States · Dendreo · fastlane-plugin-run_tests_firebase_testlab · git_credential_manager · Microsoft Git Credential Manager · RubyGems · Aikido Security · Charlie Eriksen · Maciej Mensfeld · Mend.io · Socket · StepSecurity
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
