Archynetys Live news trend intelligence
▲ Peaking Technology

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

A supply chain attack named SleeperGem is leveraging compromised RubyGems packages to drop persistent backdoors onto developer machines.

4sources
4articles
2velocity
+0%since first seen
6h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

The SleeperGem attack targets dormant maintainer accounts to distribute malicious code. Three specific RubyGems packages—git_credential_manager, Dendreo, and fastlane—have been compromised to deploy a persistent backdoor.

Coverage from The Hacker News, Aikido Security, and StepSecurity emphasizes the supply chain nature of the attack. Additionally, cyberpress.org reports that North Korean hackers are utilizing SVG images to hide OTTERCOOKIE malware for the purpose of backdooring developers.

Future developments depend on the mitigation of the compromised packages and the identification of further malware delivery methods used by the attackers.

Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 6h ago.

Quick answers

Which RubyGems packages are affected by SleeperGem?

The compromised packages are git_credential_manager, Dendreo, and fastlane.

What is the primary target of the SleeperGem attack?

The attack targets developer machines by compromising dormant maintainer accounts.

What other malware is associated with these developer targets?

According to cyberpress.org, North Korean hackers are using SVG images to hide OTTERCOOKIE malware.

Coverage (4)

Topics

Related trends