Executive Summary
Between July 18 and July 19, 2026, a coordinated supply chain attack dubbed 'SleeperGem' targeted the RubyGems registry. The attackers compromised several dormant maintainer accounts to publish malicious versions of packages including `git_credential_manager`, `Dendreo`, and `fastlane-plugin-run_tests_firebase_testlab`. These packages act as loaders that fetch second-stage payloads from a Forgejo instance at `git.disroot[.]org`.
The campaign is notable for its deliberate anti-analysis technique: it checks for over 30 environment variables common to CI/CD platforms (like GITHUB_ACTIONS or CIRCLECI) and exits if detected, ensuring the malware only detonates on local developer workstations. Once active, it establishes persistence via systemd and cron, and attempts privilege escalation to plant a setuid root shell. This high-impact campaign aims to steal credentials and maintain long-term access to developer environments.
