SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
AI Generated Image

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

The Hacker News technology

Key Points:

  • Cybersecurity researchers have identified a new software supply chain attack named SleeperGem targeting the Ruby ecosystem, involving three malicious gems published to RubyGems that serve additional payloads on developer machines.
  • The malicious gems include "git_credential_manager," which impersonates Microsoft's official tool, and two others, "Dendreo" and "fastlane-plugin-run_tests_firebase_testlab," which were dormant for years before receiving malicious updates; these releases were published without matching commits or tags.
  • The attack avoids execution in CI environments by scanning for environment variables linked to popular CI services and only activates on developer machines, where it downloads and installs persistent native daemons and attempts privilege escalation if possible.
  • Multiple packages, mostly maintained by the same account, were compromised to spread the malicious payload, with evidence suggesting more than one maintainer account was hijacked to push rogue versions to RubyGems.
  • Users who installed these gems are advised to consider their systems and secrets compromised, remove the malicious daemons and persistence mechanisms, check for unauthorized root shells, and rotate all credentials; the attack highlights the risks of dormant accounts being hijacked for supply chain attacks.

Trending Business

Trending Technology

Trending Health