P.01Cybersecurity/Supply Chain Security··5 min read
SleeperGem: The RubyGems Attack That Skips CI and Goes for Developer Laptops
Three malicious gems published from a hijacked, six-year-dormant RubyGems account are checking for CI environment variables and refusing to run there, targeting developer machines instead. Here's what SleeperGem does and how to check if you pulled it.
CybersecuritySecuritySupply Chain
Read