SleeperGem Coordinated RubyGems Publish Pattern Across Dormant and Cross-Maintainer Accounts
Detects registry-level signals of the SleeperGem RubyGems supply chain attack: a long-dormant maintainer account publishing a new gem version, the trusted Dendreo gem receiving a new version that adds git_credential_manager as a dependency, and an unrelated maintainer (fastlane-plugin-run_tests_firebase_testlab) publishing a version referencing the same dependency within a short window - indicating coordinated, multi-account compromise rather than a single takeover.
Sigma

