Wire · technology
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 19 July 2026 · Fusion42 review
SleeperGem exploited dormant RubyGems maintainer accounts to publish malicious packages, including a fake `git_credential_manager` gem that downloads and executes arbitrary binaries, and compromised at least two unrelated long-abandoned accounts to inject the malware as a dependency into trusted packages like `fastlane-plugin-run_tests_firebase_testlab` (574k downloads). This marks RubyGems' first large-scale supply-chain attack via account takeover, a pattern npm and PyPI have faced for over a year.
This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity.
◆ ◆ The Wire takeaway
Your Ruby dependencies now carry the same account-takeover risk that broke npm and PyPI twelve months ago. If you ship Ruby code, you need to audit who maintains your gems and how long their accounts have been quiet — because RubyGems has no account reactivation controls and a year of dormancy now looks like an open door.
◆ Coverage
1 source · 19 Jul 2026
◆ Related on Wire
◆ Topics