{"id":971,"date":"2026-07-23T12:39:03","date_gmt":"2026-07-23T07:09:03","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=971"},"modified":"2026-08-19T12:41:49","modified_gmt":"2026-08-19T07:11:49","slug":"sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/","title":{"rendered":"SleeperGem RubyGems Attack Targets Developer Machines and Software Supply Chains"},"content":{"rendered":"<p>A newly discovered RubyGems malware campaign, dubbed SleeperGem, demonstrates how attackers can target developer workstations by deliberately avoiding CI\/CD environments.<\/p>\n<p>Researchers found three malicious RubyGems packages that skip execution in CI\/CD environments and instead run on developer workstations, where source code, package registry tokens, SSH keys, and cloud credentials are commonly stored.<\/p>\n<p>The campaign demonstrates that developer <a href=\"https:\/\/www.hexnode.com\/blogs\/evolution-of-endpoint-security-modern-enterprises\/\">endpoint security<\/a> is becoming just as important as securing the software delivery pipeline.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tDetect and contain threats using Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>Why security teams are paying attention<\/h2>\n<p>SleeperGem skips execution in CI environments and instead runs on developer workstations. According to StepSecurity, the malicious packages check for environment variables associated with GitHub Actions, GitLab CI, Jenkins, CircleCI, Travis CI, Vercel, and other build systems. If detected, the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-malware\/\">malware<\/a> exits.<\/p>\n<p>Developer systems often have access to source code, repositories, deployment environments, and enterprise resources. Although public reporting has not confirmed credential theft, StepSecurity recommends treating affected systems and accessible secrets as potentially compromised.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-challenges.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Explore enterprise cybersecurity challenges and practical strategies to reduce security risks effectively.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h2>Why CI security alone isn&#8217;t enough<\/h2>\n<p>SleeperGem skips execution in CI\/CD environments, reducing the effectiveness of security controls focused solely on build pipelines. Instead, it executes on developer workstations, where source code, package registry tokens, deployment tools, SSH keys, and cloud credentials are often available.<\/p>\n<p>This highlights the need to extend developer endpoint security beyond CI\/CD infrastructure. Monitoring developer workstations alongside build systems provides broader visibility into software <a href=\"https:\/\/www.hexnode.com\/resources\/reports\/securing-the-supply-chain-sector-a-comprehensive-report\/\">supply chain attacks<\/a> that evade automated build pipelines.<\/p>\n<h2>How the RubyGems Malware operates<\/h2>\n<p>The campaign involved three malicious packages:<\/p>\n<ul>\n<li>git_credential_manager (versions 2.8.0\u20132.8.3), impersonating Microsoft&#8217;s Git Credential Manager<\/li>\n<li>Dendreo (versions 1.1.3 and 1.1.4)<\/li>\n<li>fastlane-plugin-run_tests_firebase_testlab (version 0.3.2)<\/li>\n<\/ul>\n<p>According to StepSecurity, each package acts as a loader that retrieves a second-stage payload from an attacker-controlled Forgejo host. On Unix systems, the payload executes through \/bin\/sh.<\/p>\n<p>Once active, the malware downloads additional scripts and binaries, installs persistence through cron jobs and systemd user services, checks membership in privileged groups, and attempts root-level persistence when passwordless sudo is available.<\/p>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 18.6047%; text-align: left;\">Attack Stage<\/th>\n<th style=\"width: 41.5433%; text-align: left;\">Observed Behavior<\/th>\n<th style=\"width: 38.7949%; text-align: left;\">Operational Impact<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 18.6047%;\">Package installation<\/td>\n<td style=\"width: 41.5433%;\">Malicious RubyGem executes loader<\/td>\n<td style=\"width: 38.7949%;\">Initiates malicious code execution on a developer workstation<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.6047%;\">Environment checks<\/td>\n<td style=\"width: 41.5433%;\">Skips execution in CI\/CD environments<\/td>\n<td style=\"width: 38.7949%;\">Focuses on developer workstations<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.6047%;\">Second stage<\/td>\n<td style=\"width: 41.5433%;\">Retrieves payloads from an attacker-controlled Forgejo host<\/td>\n<td style=\"width: 38.7949%;\">Enables execution of second-stage payloads<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.6047%;\">Persistence<\/td>\n<td style=\"width: 41.5433%;\">Creates cron jobs and systemd user services<\/td>\n<td style=\"width: 38.7949%;\">Maintains persistence across sessions<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.6047%;\">Privilege checks<\/td>\n<td style=\"width: 41.5433%;\">Checks privileged groups and passwordless sudo<\/td>\n<td style=\"width: 38.7949%;\">Increases risk on misconfigured systems<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>StepSecurity also found that Dendreo and fastlane-plugin-run_tests_firebase_testlab published malicious releases after years of dormancy, increasing the likelihood that existing users would trust the updates.<\/p>\n<p>This tactic demonstrates how attackers can exploit established package reputations as part of a software supply chain attack.<\/p>\n<h2>What security teams should verify<\/h2>\n<p>Organizations should identify whether affected package versions were installed on developer systems and check for persistence artifacts.<\/p>\n<p>StepSecurity recommends treating affected machines as compromised, removing the dropped daemon and persistence mechanisms, checking for the setuid shell at \/usr\/local\/sbin\/ping6, and rotating credentials or secrets accessible from those devices.<\/p>\n<p>Security teams should also:<\/p>\n<ul>\n<li>Review newly published versions of dormant packages before deployment.<\/li>\n<li>Validate package releases against upstream source repositories.<\/li>\n<li>Maintain approved software baselines for developer endpoints.<\/li>\n<li>Continuously monitor developer workstations alongside CI\/CD infrastructure.<\/li>\n<\/ul>\n<h2>How Hexnode supports developer endpoint security<\/h2>\n<p>SleeperGem reinforces the need to treat developer workstations as critical enterprise assets. While package validation and dependency management remain essential, endpoint management and visibility add another layer of defense.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help by:<\/p>\n<ul>\n<li>Enforcing device compliance policies.<\/li>\n<li>Maintaining approved software configurations.<\/li>\n<li>Deploying operating system and security updates.<\/li>\n<li>Providing centralized visibility into managed endpoints.<\/li>\n<\/ul>\n<p>Where deployed, Hexnode XDR can complement incident response by:<\/p>\n<ul>\n<li>Investigating endpoint activity and suspicious behavior on managed Windows and macOS endpoints through Hexnode XDR&#8217;s Investigate workspace.<\/li>\n<li>Helping security teams analyze endpoint activity, identify suspicious patterns, and correlate telemetry during investigations.<\/li>\n<\/ul>\n<p>Together, these capabilities support a layered response alongside dependency management, vulnerability remediation, and credential rotation.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Build a stronger cybersecurity strategy with practical frameworks, checklists, templates, and enterprise security implementation guides.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Conclusion<\/h2>\n<p>The RubyGems malware campaign demonstrates how software supply chain attacks can target developer endpoints instead of build infrastructure alone. By avoiding CI environments and executing on developer workstations, SleeperGem shifts attention to systems that often provide privileged access across the enterprise.<\/p>\n<p>Organizations should extend software supply chain defenses beyond dependency scanning by securing developer devices, investigating unexpected package activity, and responding quickly when compromised packages are identified.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Your Developer Endpoint Security <\/h5><p>Start your free Hexnode trial to improve endpoint visibility and compliance. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why did SleeperGem avoid CI\/CD environments?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>The malware checks for CI\/CD environment variables and exits when detected, executing on developer workstations instead of automated build systems.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why are dormant package updates risky?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Dormant packages can retain developer trust for years. Unexpected updates should be verified before deployment to reduce software supply chain risk.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How can organizations reduce the risk of malicious packages?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Validate releases against upstream repositories, review dormant package updates, maintain approved software baselines, and continuously monitor developer workstations for unusual activity.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A newly discovered RubyGems malware campaign, dubbed SleeperGem, demonstrates how attackers can target developer workstations&#8230;<\/p>\n","protected":false},"author":5,"featured_media":978,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,17],"class_list":["post-971","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-macos","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>RubyGems Malware Targets Developer Machines with SleeperGem<\/title>\n<meta name=\"description\" content=\"Learn how the SleeperGem RubyGems malware campaign targets developer workstations using malicious packages in a software supply chain attack.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"RubyGems Malware Targets Developer Machines with SleeperGem\" \/>\n<meta property=\"og:description\" content=\"Learn how the SleeperGem RubyGems malware campaign targets developer workstations using malicious packages in a software supply chain attack.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-23T07:09:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T07:11:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/rubygems-malware.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"SleeperGem RubyGems Attack Targets Developer Machines and Software Supply Chains\",\"datePublished\":\"2026-07-23T07:09:03+00:00\",\"dateModified\":\"2026-08-19T07:11:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/\"},\"wordCount\":881,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/rubygems-malware.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"macOS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/\",\"name\":\"RubyGems Malware Targets Developer Machines with SleeperGem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/rubygems-malware.jpeg?format=webp\",\"datePublished\":\"2026-07-23T07:09:03+00:00\",\"dateModified\":\"2026-08-19T07:11:49+00:00\",\"description\":\"Learn how the SleeperGem RubyGems malware campaign targets developer workstations using malicious packages in a software supply chain attack.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/rubygems-malware.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/rubygems-malware.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"rubygems malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SleeperGem RubyGems Attack Targets Developer Machines and Software Supply Chains\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"RubyGems Malware Targets Developer Machines with SleeperGem","description":"Learn how the SleeperGem RubyGems malware campaign targets developer workstations using malicious packages in a software supply chain attack.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/","og_locale":"en_US","og_type":"article","og_title":"RubyGems Malware Targets Developer Machines with SleeperGem","og_description":"Learn how the SleeperGem RubyGems malware campaign targets developer workstations using malicious packages in a software supply chain attack.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-23T07:09:03+00:00","article_modified_time":"2026-08-19T07:11:49+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/rubygems-malware.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"SleeperGem RubyGems Attack Targets Developer Machines and Software Supply Chains","datePublished":"2026-07-23T07:09:03+00:00","dateModified":"2026-08-19T07:11:49+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/"},"wordCount":881,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/rubygems-malware.jpeg?format=webp","articleSection":["Identity Abuse","macOS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/","url":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/","name":"RubyGems Malware Targets Developer Machines with SleeperGem","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/rubygems-malware.jpeg?format=webp","datePublished":"2026-07-23T07:09:03+00:00","dateModified":"2026-08-19T07:11:49+00:00","description":"Learn how the SleeperGem RubyGems malware campaign targets developer workstations using malicious packages in a software supply chain attack.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/rubygems-malware.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/rubygems-malware.jpeg?format=webp","width":1340,"height":700,"caption":"rubygems malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/sleepergem-rubygems-attack-targets-developer-machines-and-software-supply-chains\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"SleeperGem RubyGems Attack Targets Developer Machines and Software Supply Chains"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/971","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=971"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/971\/revisions"}],"predecessor-version":[{"id":980,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/971\/revisions\/980"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/978"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}