malware
rubygems
Dendreo
discovered 2026-07-19Long-dormant RubyGems package (first published 2017, quiet since ~2019) whose maintainer account was taken over and reactivated. Received two new versions around the same time as git_credential_manager; the attacker added git_credential_manager as a runtime dependency so installing or using Dendreo transitively pulls in the dropper. Exact malicious version numbers not disclosed in source.
Threat types
other
Malicious versions
- unknown