Published July 19, 2026 ยท Added August 3, 2026

SleeperGem: Compromised RubyGems Drop a Persistent Backdoor

StepSecurity analyzes the SleeperGem supply-chain attack, where compromised RubyGems packages targeted developer machines rather than CI runners, fetched payloads from a Forgejo instance, and installed persistent malware after dormant maintainer accounts were abused.

StepSecurity analyzes the SleeperGem supply-chain attack, where compromised RubyGems packages targeted developer machines rather than CI runners, fetched payloads from a Forgejo instance, and installed persistent malware after dormant maintainer accounts were abused.

Read the original story.

Source: Stepsecurity