SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.

Read more at The Hacker News.

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines - Newsroom The Hacker News e1779879940852

About Mend.io

Mend.io is built for every risk, across AI and AppSec. By securing the code layer and the AI layerβ€”and the interactions between them, where modern application risk now livesβ€”Mend.io extends proven AppSec workflows to the models, prompts, and agents inside today’s applications, delivering continuous protection across the entire AI application lifecycle.