Post #4103733
2026-07-21 16:09 UTC
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
https://www.aikido.dev/blog/sleepergem-rubygems-supply-chain-attack
> It's not often we see a supply chain attack on RubyGems. But with summer vacations in full swing, perhaps we should have expected one. It was still a surprise when I opened the triage queue this morning and found a suspicious new package waiting.
> At first glance, all it appeared to do was download some binaries from a host I'd never seen before. Surely that couldn't be malicious... right?
Replies (0)
No replies.