SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
Read more at The Hacker News.
About Mend.io
Mend.io is built for every risk, across AI and AppSec. By securing the code layer and the AI layerβand the interactions between them, where modern application risk now livesβMend.io extends proven AppSec workflows to the models, prompts, and agents inside today’s applications, delivering continuous protection across the entire AI application lifecycle.