SleeperGem Attack Hid Malware in Dormant RubyGems Packages for Years Before Striking Developer Machines
The SleeperGem supply chain attack reactivated packages dormant since 2017, impersonated Microsoft's Git Credential Manager, and avoided CI/CD detection. Here's how it worked and what to check on your systems.