SleeperGem Uses Three RubyGems to Compromise Dev Machines

Security researchers uncovered SleeperGem, a three-package RubyGems supply-chain attack: git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab were repackaged as loaders that fetch a second-stage payload from a Forgejo host; the malware avoids CI environments, drops a native daemon on developer machines, installs persistence via cron and a systemd user service, and can even plant a setuid root shell at /usr/local/sbin/ping6 if sudo is passwordless. The rogue gems spread by being added as dependencies to other gems. Remediation includes removing the dropped daemon from ~/.local/share/gcm/, erasing persistence mechanisms, and rotating credentials.
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines The Hacker News
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor StepSecurity
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts Aikido Security
- North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers cyberpress.org
- Supply Chain Vulnerability in RubyGems Highlights Growing Software Security Risks TipRanks
Reading Insights
1
26
4 min
vs 5 min read
89%
812 → 87 words
Want the full story? Read the original article
Read on The Hacker News