Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious RubyGems Packages Threaten Developer Security

Malicious RubyGems Packages Threaten Developer Security

Posted on July 20, 2026 By CWS

In a recent cybersecurity alert, researchers have identified a new supply chain attack within the Ruby ecosystem, dubbed SleeperGem. This threat involves three malicious packages uploaded to RubyGems, aiming to deliver additional harmful payloads to developers’ systems.

Details of the SleeperGem Attack

StepSecurity conducted an analysis, revealing that these malicious packages act as loaders. They retrieve a second-stage payload from a Forgejo server controlled by attackers. This payload is designed to bypass build systems but targets developer machines, where it deploys a native daemon and ensures persistence.

A distinctive feature of this attack is the impersonation of the official Microsoft Git Credential Manager by a package named git_credential_manager. Other affected packages include Dendreo and fastlane-plugin-run_tests_firebase_testlab, which had been inactive for years before receiving harmful updates. Notably, these packages were uploaded to the registry without corresponding source project commits or tags.

How the Attack Propagates

The malicious git_credential_manager has been added as a dependency to several packages, including Dendreo and fastlane-plugin-run_tests_firebase_testlab. This method facilitates the spread of malicious code to existing users. Most of these packages, excluding fastlane-plugin-run_tests_firebase_testlab, are maintained by a single account known as ‘LR-DEV’. However, the presence of multiple compromised accounts suggests a broader infiltration strategy.

Once installed, the malware scans systems for environment variables related to continuous integration (CI) services such as GitHub Actions and Jenkins. If detected, the malware terminates to avoid execution on ephemeral CI environments, ensuring it only runs on developer machines.

Implications and Recommendations

The attack’s severity is illustrated by the behavior of git_credential_manager, which downloads and executes payloads via PowerShell on Windows. While version 2.8.2 simply stages these payloads, version 2.8.3 escalates the attack by launching a background daemon and establishing persistence through cron jobs and systemd services.

Security experts urge users of the affected packages to consider their systems and credentials compromised. They recommend removing the embedded daemon, eradicating persistence mechanisms, and rotating all sensitive credentials. Additionally, users should inspect for any unauthorized setuid shells being used within their systems.

The SleeperGem incident highlights the vulnerabilities of seemingly inactive accounts within software repositories. As Aikido Security’s Charlie Eriksen noted, the dormant state of these accounts made them prime targets for hijacking.

In a broader context, RubyGems has previously faced similar threats, including a recent spam campaign that temporarily halted account sign-ups. These events underscore the need for heightened vigilance and security practices to protect the integrity of software supply chains.

The Hacker News Tags:Cybersecurity, data exfiltration, developer security, Git, malicious packages, Malware, Open Source, RubyGems, software supply chain, Vulnerability

Post navigation

Previous Post: Critical WordPress Flaws WP2Shell Actively Exploited
Next Post: Russian Nationals Charged in $62M Cybercrime Case

Related Posts

Critical React Native CLI Flaw Exposed Millions of Developers to Remote Attacks Critical React Native CLI Flaw Exposed Millions of Developers to Remote Attacks The Hacker News
Unveiling Cyber Deception: Lessons from Art Forgery Unveiling Cyber Deception: Lessons from Art Forgery The Hacker News
Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities The Hacker News
Xinbi Telegram Market Tied to .4B in Crypto Crime, Romance Scams, North Korea Laundering Xinbi Telegram Market Tied to $8.4B in Crypto Crime, Romance Scams, North Korea Laundering The Hacker News
Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild The Hacker News
Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark