Software Supply Chain Attacks: RubyGems Dormant Account Hijack, Front-End JS Compromise, and IDE Attacks
Key Questions
What was the SleeperGem attack on RubyGems?
Attackers hijacked two long-inactive maintainer accounts to push a malicious gem that disabled SSL verification for binary downloads. It is the first known supply chain attack of this type on RubyGems.
How did the Polymarket incident occur?
Polymarket lost $3M through a front-end supply chain attack that compromised a third-party JavaScript library. The incident exposed gaps in runtime monitoring beyond static dependency scanning.
What platform did Deloitte launch?
Deloitte introduced an AI-driven software supply chain security platform powered by Claude. It targets the remediation gap across open-source, commercial, and custom code.
Why do dormant accounts pose a supply chain risk?
The SleeperGem attack demonstrates that long-inactive maintainer accounts can be hijacked to distribute malicious packages. Auditing dormant accounts across registries is now a recommended practice.
What broader signal do these attacks send?
Both the RubyGems and Polymarket incidents reinforce the need for continuous software supply chain security investments. They mirror patterns previously seen on npm and PyPI.
A new supply chain attack on RubyGems (SleeperGem) hijacked two long-inactive maintainer accounts to push a malicious gem that downloads binaries with SSL verification disabled. This is the first such attack on RubyGems, mirroring patterns seen on npm and PyPI. It reinforces the need for auditing dormant accounts across all registries and is a strong signal for software supply chain security investments. Polymarket lost $3M via front-end supply chain attack (compromised third-party JavaScript), highlighting runtime monitoring gap beyond static analysis and dependency scanning. A new TeamPCP attack on VS Code extensions exfiltrated 3,800 repos, highlighting developer supply chain risk and the need for Agentic Endpoint Security (AES). Deloitte launched an AI-driven software supply chain security platform powered by Claude, addressing the remediation gap across open-source, commercial, and custom code. Risk Ledger secured £24m Series B for network-based TPRM, signaling supply chain security momentum. A new FT piece quotes Darktrace, Palo Alto, Sophos, Mandiant on supply chains as the weakest link, reinforcing the trend.