Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious RubyGems Packages Threaten Developer Security

Malicious RubyGems Packages Threaten Developer Security

Posted on July 20, 2026 By CWS

In a recent cybersecurity alert, researchers have identified a new supply chain attack within the Ruby ecosystem, dubbed SleeperGem. This threat involves three malicious packages uploaded to RubyGems, aiming to deliver additional harmful payloads to developers’ systems.

Details of the SleeperGem Attack

StepSecurity conducted an analysis, revealing that these malicious packages act as loaders. They retrieve a second-stage payload from a Forgejo server controlled by attackers. This payload is designed to bypass build systems but targets developer machines, where it deploys a native daemon and ensures persistence.

A distinctive feature of this attack is the impersonation of the official Microsoft Git Credential Manager by a package named git_credential_manager. Other affected packages include Dendreo and fastlane-plugin-run_tests_firebase_testlab, which had been inactive for years before receiving harmful updates. Notably, these packages were uploaded to the registry without corresponding source project commits or tags.

How the Attack Propagates

The malicious git_credential_manager has been added as a dependency to several packages, including Dendreo and fastlane-plugin-run_tests_firebase_testlab. This method facilitates the spread of malicious code to existing users. Most of these packages, excluding fastlane-plugin-run_tests_firebase_testlab, are maintained by a single account known as ‘LR-DEV’. However, the presence of multiple compromised accounts suggests a broader infiltration strategy.

Once installed, the malware scans systems for environment variables related to continuous integration (CI) services such as GitHub Actions and Jenkins. If detected, the malware terminates to avoid execution on ephemeral CI environments, ensuring it only runs on developer machines.

Implications and Recommendations

The attack’s severity is illustrated by the behavior of git_credential_manager, which downloads and executes payloads via PowerShell on Windows. While version 2.8.2 simply stages these payloads, version 2.8.3 escalates the attack by launching a background daemon and establishing persistence through cron jobs and systemd services.

Security experts urge users of the affected packages to consider their systems and credentials compromised. They recommend removing the embedded daemon, eradicating persistence mechanisms, and rotating all sensitive credentials. Additionally, users should inspect for any unauthorized setuid shells being used within their systems.

The SleeperGem incident highlights the vulnerabilities of seemingly inactive accounts within software repositories. As Aikido Security’s Charlie Eriksen noted, the dormant state of these accounts made them prime targets for hijacking.

In a broader context, RubyGems has previously faced similar threats, including a recent spam campaign that temporarily halted account sign-ups. These events underscore the need for heightened vigilance and security practices to protect the integrity of software supply chains.

The Hacker News Tags:Cybersecurity, data exfiltration, developer security, Git, malicious packages, Malware, Open Source, RubyGems, software supply chain, Vulnerability

Post navigation

Previous Post: Critical WordPress Flaws WP2Shell Actively Exploited
Next Post: Russian Nationals Charged in $62M Cybercrime Case

Related Posts

How to Close Threat Detection Gaps: Your SOC’s Action Plan How to Close Threat Detection Gaps: Your SOC’s Action Plan The Hacker News
Enhance SOC Efficiency with Three Key Process Improvements Enhance SOC Efficiency with Three Key Process Improvements The Hacker News
Securing Data in the AI Era Securing Data in the AI Era The Hacker News
APT28 Exploits Microsoft Office Flaw in Malware Attacks APT28 Exploits Microsoft Office Flaw in Malware Attacks The Hacker News
From Triage to Threat Hunts: How AI Accelerates SecOps From Triage to Threat Hunts: How AI Accelerates SecOps The Hacker News
Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ServiceNow Vulnerability Exploited Post-Disclosure
  • wp2shell Vulnerability Exploitation Escalates
  • Addressing Identity Fragmentation in Cybersecurity
  • ENCFORGE Ransomware Hits AI Files in Langflow Attack
  • Integrating CBOM Solutions in Modern Architecture

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ServiceNow Vulnerability Exploited Post-Disclosure
  • wp2shell Vulnerability Exploitation Escalates
  • Addressing Identity Fragmentation in Cybersecurity
  • ENCFORGE Ransomware Hits AI Files in Langflow Attack
  • Integrating CBOM Solutions in Modern Architecture

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark