A coordinated RubyGems supply-chain attack dubbed SleeperGem used malicious releases of git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab to target developer workstations. Researchers reported that the attacker appears to have hijacked long-dormant maintainer accounts and pushed trojanized gem versions, including git_credential_manager 2.8.0 through 2.8.3, with code that executed on library load, fetched additional payloads from a fake-looking Git ecosystem repository on git.disroot.org, and deliberately avoided running in CI environments to reduce detection.
On developer machines, the gems reportedly acted as loaders for a second stage that installed a native daemon, established persistence through systemd and cron, and attempted privilege escalation via passwordless sudo to place a setuid root shell at /usr/local/sbin/ping6. Investigators said the malicious releases did not match legitimate source tags and that some affected packages had been inactive for years before suddenly publishing updates, indicating account compromise rather than normal maintenance. Security firms warned that any system that installed or required the affected gems should be treated as fully compromised and that all accessible credentials and secrets should be rotated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On July 19, 2026, Aikido and StepSecurity published analyses identifying the SleeperGem campaign and detailing how the malicious gems fetched second-stage payloads from git.disroot.org while avoiding CI environments. StepSecurity reported that the payload established persistence via systemd and cron and attempted privilege escalation by installing a setuid root shell at /usr/local/sbin/ping6.
Between July 18 and July 19, 2026, attackers published malicious versions of the RubyGems packages git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab. The activity was described as a coordinated supply-chain attack involving dormant or compromised maintainer accounts and malicious updates that did not match legitimate source tags.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourceaikido.dev
Open sourcestepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.