Find notable cyber news and cases, enriched with sources, timelines, and signals.

SleeperGem RubyGems supply-chain campaign

Campaign
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer machines. The operation is significant because the rogue releases were pushed directly to RubyGems from likely compromised or dormant accounts, letting the malicious code spread to existing users of the packages.

Related Happenings

RubyGems.org dead drop for stolen credential data

Data Leak
H score11 First: 20.07.2026 08:15 Last: 20.07.2026 08:15 Sources 1

How related: "The haul included plaintext passwords, SSH private keys, AWS credentials, crypto wallet seed phrases, Social Security numbers, credit card numbers, and bank account details across 63 vault items," Maciej Mensfeld said.

About this happening: A malicious browser extension used RubyGems.org as a dead drop for stolen credential data, exposing 63 vault items with passwords, keys, and financial details. The upl...

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....

Mastra @mastra/* npm packages hit by network compromise

Incident
H score47 First: 17.06.2026 10:38 Last: 17.06.2026 10:38 Sources 1

About this happening: Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...

Latest development: 20.06.2026 17:09

Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.

North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale

Threat Actor Meta
H score31 First: 15.06.2026 22:32 Last: 15.06.2026 22:32 Sources 1

About this happening: North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...

Timeline

  1. 20.07.2026 08:15 1 articles · 17h ago

    Malicious Dendreo gem versions are published to RubyGems

    Campaign Scope Update

    Dendreo versions 1.1.3 and 1.1.4 are published to RubyGems as part of the SleeperGem supply-chain activity, with the malicious releases later described as loaders that can fetch a second stage and affect existing users of the package.

    Show sources
  2. 20.07.2026 08:15 1 articles · 17h ago

    Malicious fastlane-plugin-run_tests_firebase_testlab version is published to RubyGems

    Campaign Scope Update

    fastlane-plugin-run_tests_firebase_testlab version 0.3.2 is published to RubyGems as another malicious SleeperGem loader, extending the campaign beyond the newer git_credential_manager impersonation.

    Show sources
  3. 20.07.2026 08:15 1 articles · 17h ago

    Malicious git_credential_manager versions are published to RubyGems

    Campaign Scope Update

    git_credential_manager versions 2.8.0, 2.8.1, 2.8.2, and 2.8.3 are published to RubyGems while impersonating Microsoft Git Credential Manager, and version 2.8.3 later advances the attack by launching a background daemon, establishing persistence, and probing for sudo escalation on developer machines.

    Show sources
  4. 20.07.2026 08:15 2 articles · 17h ago

    Researchers flag the SleeperGem RubyGems supply-chain campaign

    Initial Disclosure

    Researchers flag SleeperGem as a software supply-chain attack against the Ruby ecosystem after three malicious gems are published to RubyGems; the releases act as loaders, skip CI environments, and are intended to run on developer machines where they can install persistence and deliver a second stage.

    Show sources