DigiNews

Tech Watch by Johan Denoyer

← Back to articles

SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts

Quality: 8/10 Relevance: 9/10

Summary

SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts reveals a supply chain compromise where a new gem, git_credential_manager, was published with malicious payloads. The article details the attack stages, including downloading binaries from a Forgejo host, evading SSL checks, and loading a dropper via the gem's load path, underscoring open-source dependency risk and the importance of monitoring dormant or dormant-like maintainers.

🚀 Service construit par Johan Denoyer