RubyGems has joined npm and PyPI as a supply-chain target. Three malicious packages used require-time execution and CI evasion to compromise developer workstations. # Cybersecurity https:// deafnews.i

RubyGems has joined npm and PyPI as a supply-chain target. Three malicious packages used require-time execution and CI evasion to compromise developer workstations. # Cybersecurity https:// deafnews.it/en/article/sleeper gem-the-day-rubygems-became-an-npm-style-target

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

RubyGems has joined npm and PyPI as a supply-chain target. Three malicious packages used require-time execution and CI evasion to compromise developer workstations. # Cybersecurity https:// deafnews.i

mastodon:infosec-exchangeother65d ago kagi ↗

RubyGems has joined npm and PyPI as a supply-chain target. Three malicious packages used require-time execution and CI evasion to compromise developer workstations. # Cybersecurity https:// deafnews.it/en/article/sleeper gem-the-day-rubygems-became-an-npm-style-target