SleeperGem RubyGems Supply Chain Attack Analysis
Score: 9/10

SleeperGem RubyGems Supply Chain Attack Analysis

The SleeperGem campaign involves compromised RubyGems that drop a persistent backdoor and native daemon specifically targeting developer machines while evading CI/CD environments.

Executive Summary

Between July 18 and July 19, 2026, a coordinated supply chain attack dubbed 'SleeperGem' targeted the RubyGems registry. The attackers compromised several dormant maintainer accounts to publish malicious versions of packages including `git_credential_manager`, `Dendreo`, and `fastlane-plugin-run_tests_firebase_testlab`. These packages act as loaders that fetch second-stage payloads from a Forgejo instance at `git.disroot[.]org`.

The campaign is notable for its deliberate anti-analysis technique: it checks for over 30 environment variables common to CI/CD platforms (like GITHUB_ACTIONS or CIRCLECI) and exits if detected, ensuring the malware only detonates on local developer workstations. Once active, it establishes persistence via systemd and cron, and attempts privilege escalation to plant a setuid root shell. This high-impact campaign aims to steal credentials and maintain long-term access to developer environments.

Key Details

Threat Name

SleeperGem

Affects

—

Adversary

SleeperGem

Malware/Tools

SleeperGem, git_credential_manager, Dendreo, fastlane-plugin-run_tests_firebase_testlab

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure10
Technical Depth8

Sources