SleeperGem RubyGems supply-chain campaign
Campaign
Summary
Hide ▲
Show ▼
SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer machines. The operation is significant because the rogue releases were pushed directly to RubyGems from likely compromised or dormant accounts, letting the malicious code spread to existing users of the packages.
Related Happenings
RubyGems.org dead drop for stolen credential data
Data Leak
H score11
First: 20.07.2026 08:15
Last: 20.07.2026 08:15
Sources 1
How related:
"The haul included plaintext passwords, SSH private keys, AWS credentials, crypto wallet seed phrases, Social Security numbers, credit card numbers, and bank account details across 63 vault items," Maciej Mensfeld said.
About this happening:
A malicious browser extension used RubyGems.org as a dead drop for stolen credential data, exposing 63 vault items with passwords, keys, and financial details. The upl...
RubyGems.org dead drop for stolen credential data
Data LeakHow related: "The haul included plaintext passwords, SSH private keys, AWS credentials, crypto wallet seed phrases, Social Security numbers, credit card numbers, and bank account details across 63 vault items," Maciej Mensfeld said.
About this happening: A malicious browser extension used RubyGems.org as a dead drop for stolen credential data, exposing 63 vault items with passwords, keys, and financial details. The upl...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
Mastra @mastra/* npm packages hit by network compromise
Incident
H score47
First: 17.06.2026 10:38
Last: 17.06.2026 10:38
Sources 1
About this happening:
Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Mastra @mastra/* npm packages hit by network compromise
IncidentAbout this happening: Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Latest development: 20.06.2026 17:09
Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.
North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale
Threat Actor Meta
H score31
First: 15.06.2026 22:32
Last: 15.06.2026 22:32
Sources 1
About this happening:
North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...
North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale
Threat Actor MetaAbout this happening: North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...
Timeline
-
20.07.2026 08:15 1 articles · 17h ago
Malicious Dendreo gem versions are published to RubyGems
Campaign Scope UpdateDendreo versions 1.1.3 and 1.1.4 are published to RubyGems as part of the SleeperGem supply-chain activity, with the malicious releases later described as loaders that can fetch a second stage and affect existing users of the package.
Show sources
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — thehackernews.com — 20.07.2026 08:15
-
20.07.2026 08:15 1 articles · 17h ago
Malicious fastlane-plugin-run_tests_firebase_testlab version is published to RubyGems
Campaign Scope Updatefastlane-plugin-run_tests_firebase_testlab version 0.3.2 is published to RubyGems as another malicious SleeperGem loader, extending the campaign beyond the newer git_credential_manager impersonation.
Show sources
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — thehackernews.com — 20.07.2026 08:15
-
20.07.2026 08:15 1 articles · 17h ago
Malicious git_credential_manager versions are published to RubyGems
Campaign Scope Updategit_credential_manager versions 2.8.0, 2.8.1, 2.8.2, and 2.8.3 are published to RubyGems while impersonating Microsoft Git Credential Manager, and version 2.8.3 later advances the attack by launching a background daemon, establishing persistence, and probing for sudo escalation on developer machines.
Show sources
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — thehackernews.com — 20.07.2026 08:15
-
20.07.2026 08:15 2 articles · 17h ago
Researchers flag the SleeperGem RubyGems supply-chain campaign
Initial DisclosureResearchers flag SleeperGem as a software supply-chain attack against the Ruby ecosystem after three malicious gems are published to RubyGems; the releases act as loaders, skip CI environments, and are intended to run on developer machines where they can install persistence and deliver a second stage.
Show sources
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — thehackernews.com — 20.07.2026 08:15
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — thehackernews.com — 20.07.2026 08:15