Bundler's Cooldown Feature Could Have Blocked SleeperGem Supply Chain Attack
On July 19, 2026, Aikido Security disclosed a Ruby gem supply chain attack dubbed SleeperGem, involving malicious versions of three gems — git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab. The malicious releases exploited dormant, trusted gem accounts, with two gems having been inactive since 2019 and 2020. The attack payload was designed to evade CI environments by detecting roughly 30 CI-related environment variables, instead activating on developer machines where it installed a persistent daemon and, if run as root, a setuid shell. Notably, Bundler 4.0.13 had shipped a 'cooldown' feature on June 3 — 45 days earlier — which prevents resolving gem versions newer than a specified number of days, a safeguard that would have blocked all malicious releases during their entire window of availability. Widely circulated reports about the incident contained inaccurate publication dates and inflated download figures that did not reflect the actual reach of the malicious versions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in