SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
Summary
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts reveals a supply chain compromise where a new gem, git_credential_manager, was published with malicious payloads. The article details the attack stages, including downloading binaries from a Forgejo host, evading SSL checks, and loading a dropper via the gem's load path, underscoring open-source dependency risk and the importance of monitoring dormant or dormant-like maintainers.