VDB

GCVE-110-OSM-2026-8741

GCVE-110-OSM-2026-8741
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 19, 2026
Legitimate Fastlane plugin with 574,661 total downloads whose dormant maintainer account was hijacked as part of the SleeperGem campaign. A different compromised account from the Dendreo gem was used, indicating the attacker had access to multiple dormant RubyGems accounts. The attacker added the malicious git_credential_manager gem as a dependency to propagate the backdoor to the plugin's large install base. === DORMANT ACCOUNT HIJACKING === Total gem downloads: 574,661 Different maintainer account compromised than Dendreo Both accounts were long-dormant and reactivated within hours of each other === DEPENDENCY INJECTION === Malicious dependency added: git_credential_manager Payload delivery: Indirect via dependency chain High-impact target due to large download count and Fastlane/mobile CI usage

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownfastlane-plugin-run_tests_firebase_testlaball (affected)

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›