SleeperGem은 Ruby 생태계에서 개발자 기계를 겨냥한 새로운 소프트웨어 공급망 공격이다.
사이버 보안 연구자들이 'SleeperGem'이라는 새로운 소프트웨어 공급망 공격을 경고하고 있다. 이 공격은 Ruby 생태계에서 세 개의 악성 RubyGems 패키지를 통해 진행되며, 추가적인 페이로드를 제공하는 것을 목표로 한다. 이 악성 젬들은 git_credential_manager 및 Dendreo와 같은 다양한 버전으로 게시되었다.
SleeperGem is a new software supply chain attack targeting developer machines in the Ruby ecosystem.
Cybersecurity researchers have flagged a new software supply chain attack named 'SleeperGem' targeting the Ruby ecosystem. This attack is conducted through three malicious RubyGems packages aimed at serving additional payloads. The rogue gems include various versions of git_credential_manager and Dendreo, which have been published recently.