INTEL_REPORT
The Hacker News · published 7/20/2026, 5:15:39 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) - SleeperGem Us…
https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
sha256:fb20f8e4b6f4ec142272ec0f407abf29ef1507162f46ba33bf01f326048736b0
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.