SleeperGem is a software supply chain attack targeting the Ruby ecosystem through three malicious RubyGems packages. The malware acts as a loader, fetching second-stage payloads from an attacker-controlled Forgejo host. It checks for CI environment variables to avoid detection on build systems, and on developer machines it drops a native daemon, establishes persistence via cron and systemd, and escalates privileges if possible.