BufferZoneCorp sleeper attack on RubyGems + Go modules
Socket disclosed a coordinated sleeper-package campaign attributed to the GitHub org BufferZoneCorp (and RubyGems user knot-theory). Initially-clean Ruby gems and Go modules were updated to malicious versions. The Ruby side harvests env vars, SSH keys, AWS secrets, .npmrc, .netrc, GitHub CLI config, and RubyGems credentials; the Go side tampers with GitHub Actions workflows, injects fake executables, and adds SSH persistence via authorized_keys. First confirmed 2026 RubyGems + Go module supply-chain campaign.
Versions named here: