CyberSecurityBoardThreat Intel · CVEs · Products
Malware

SleeperGem: RubyGems Supply Chain Attack

July 20, 2026

SleeperGem is a software supply chain attack targeting the Ruby ecosystem through three malicious RubyGems packages. The malware acts as a loader, fetching second-stage payloads from an attacker-controlled Forgejo host. It checks for CI environment variables to avoid detection on build systems, and on developer machines it drops a native daemon, establishes persistence via cron and systemd, and escalates privileges if possible.