Skip to content

Feature request: inventory installed RubyGems — dev-machine-targeting campaigns (SleeperGem) are the ones DMG can't sweep #176

Description

@arcaven

Why

SleeperGem-class campaigns are engineered for exactly the surface Dev Machine Guard owns — the SleeperGem loaders inspect ~30 CI environment variables and skip execution in CI so the payload only detonates on developer workstations. But DMG's package inventory today covers npm, Python, brew, and system packages — not RubyGems. So for the one campaign class that deliberately targets dev machines, the dev-machine product can't answer "is the compromised package installed on any of my fleet?", and customers are left with the campaign-specific suspicious-files detections rather than the generic inventory sweep that works for npm/Python.

We run DMG across our whole Mac fleet and sweep every Threat Center advisory against the device inventory via the developer-mdm API; RubyGems is the gap we have to hand-wave every time (our tooling now fails loud on Ruby advisories rather than pretend the sweep ran).

Ask

  • Collect installed gems in the agent scan (system ruby + rbenv/rvm/asdf installs; gem list equivalent), like the existing npm/Python collection.
  • Expose them through the same bulk package-search API endpoint pattern (.../developer-mdm/ruby-packages/search) so advisory-driven fleet sweeps work uniformly across ecosystems.

Additive only — a new collector and endpoint; no change to existing scans.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions