Wire · founder news, decoded · technology
SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
◆ Published
19 July 2026
◆ Topic
technology
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 19 July 2026 · Fusion42 review
SleeperGem exploited dormant RubyGems maintainer accounts to publish malicious packages, including a fake `git_credential_manager` gem that downloads and executes arbitrary binaries, and compromised at least two unrelated long-abandoned accounts to inject the malware as a dependency into trusted packages like `fastlane-plugin-run_tests_firebase_testlab` (574k downloads). This marks RubyGems' first large-scale supply-chain attack via account takeover, a pattern npm and PyPI have faced for over a year.
This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
Your Ruby dependencies now carry the same account-takeover risk that broke npm and PyPI twelve months ago. If you ship Ruby code, you need to audit who maintains your gems and how long their accounts have been quiet — because RubyGems has no account reactivation controls and a year of dormancy now looks like an open door.
◆ Related on Wire
- npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk10 July 2026
- AsyncAPI npm organization compromised, 2M weekly downloads affected14 July 2026
- GitHub Actions Gets Secure-by-Default CI/CD: Backport Shuts the Pwn Request Window20 July 2026
- GitLost: GitHub's AI Agent Tricked Into Leaking Private Repository Data8 July 2026
- GitHub's public APIs are becoming an enterprise reconnaissance tool10 July 2026
- New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here18 July 2026
◆ Topics
Developer Tools · Cybersecurity · rubygems-attack · package-registry-security · dormant-account-hijack · dependency-injection · developer-risk