SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
aikido.dev | incident | #supply-chain | #featured | #ruby | #incident-response | #malware | #credential-theft | #rubygems | #aikido | #dropper
Summary
It's not often we see a supply chain attack on RubyGems. But with summer vacations in full swing, perhaps we should have expected one. It was still a surprise when I opened the triage queue this morning and found a suspicious new package waiting.
- Published
- Collected
Skip to content