Security researchers have uncovered an active Ruby supply chain attack dubbed **SleeperGem**, in which three malicious packages were published to the RubyGems registry with the explicit goal of steali