✦ For YouGeopoliticsTechFinanceHealthEnergySportsCulture◆ SN Last Week★ Saved

SleeperGem Attack Hijacks Dormant RubyGems to Hit Devs

By The Hacker News · Summarized & edited by · 2026-07-20
SleeperGem Attack Hijacks Dormant RubyGems to Hit Devs

Get the Tech newsletter

Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.

Why it matters: Any developer machine that installed the affected gems must be treated as compromised: the payload establishes persistence as a daemon, plants a setuid root shell if sudo is unrestricted, and exfiltrates credentials — and because git_credential_manager was wired in as a dependency to five other packages, the blast radius extends to anyone who trusted those downstream gems. The technique of reviving years-dormant accounts shows that registry hygiene alone cannot catch hijacks, since accounts idle since 2017–2020 looked harmless to observers.

Share this story

More tech → Read original →

Get the Tech newsletter

Curated tech stories, every morning. Free.

No spam. Unsubscribe anytime.