malware rubygems

Dendreo

discovered 2026-07-19

Long-dormant RubyGems package (first published 2017, quiet since ~2019) whose maintainer account was taken over and reactivated. Received two new versions around the same time as git_credential_manager; the attacker added git_credential_manager as a runtime dependency so installing or using Dendreo transitively pulls in the dropper. Exact malicious version numbers not disclosed in source.

Threat types

other

Malicious versions

  • unknown

Techniques

Read the full analysis →