⌁ CyberSecurityBoardThreat Intel · CVEs · Products

Tag: supply chain attack

Malware

SleeperGem: RubyGems Supply Chain Attack

SleeperGem is a software supply chain attack targeting the Ruby ecosystem through three malicious RubyGems packages. The malware acts as a loader,…

malware persistence privilege escalation RubyGems
July 20, 2026
Malware

Shai-Hulud Worm: Self-Replicating npm Malware

A self-replicating worm that hit more than 500 npm packages in September 2025, harvesting developer secrets and republishing itself with stolen tokens.

2025 npm self-replicating Shai-Hulud worm
July 14, 2026