Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts

Summary

It's not often we see a supply chain attack on RubyGems. But with summer vacations in full swing, perhaps we should have expected one. It was still a surprise when I opened the triage queue this morning and found a suspicious new package waiting.
Published
Collected

original ↗

Related coverage

back