BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

60 Malicious Packages Target RubyGems, PyPI in Credential Theft Campaign

Malicious RubyGems and PyPI Packages Exploit Social Media and Crypto Users, Prompting New Security Measures

  • Sixty malicious software packages targeted the RubyGems platform by disguising as automation tools for social media and messaging.
  • The compromised packages have been available since at least March 2023 and were downloaded over 275,000 times, according to Socket.
  • Attackers used these tools to steal user credentials, especially focusing on Windows users in South Korea.
  • The Python Package Index (PyPI) was also found to contain fake packages designed to steal cryptocurrency from Bittensor wallets.
  • In response to these attacks, PyPI announced new measures to prevent confusion attacks and will soon reject certain malicious package uploads.

A group of 60 harmful software packages was uncovered on the RubyGems platform, posing as legitimate automation tools for websites like Instagram, Twitter, TikTok, and Telegram. These tools, active since at least March 2023, were published under several different aliases and aimed to steal user credentials.

- Advertisement -

The packages have been downloaded more than 275,000 times, though this number does not represent confirmed infections. Some downloads occurred on the same computers or did not result in the software being run. Socket, the company that identified the activity, stated that the packages offered real functionalities but also secretly gathered usernames and passwords through simple user interfaces.

According to researcher Kirill Boychenko, the attackers pretended to offer features like bulk posting or engagement but tricked users into giving up sensitive information. “Each gem functions as a Windows-targeting infostealer, primarily (but not exclusively) aimed at South Korean users, as evidenced by Korean-language UIs and exfiltration to .kr domains,” Socket explained. Attackers sent stolen data to servers advertising bulk social media tools, such as programzon[.]com and appspace[.]kr.

Some of these malicious tools also targeted finance-focused forums, promoting features like flooding investment discussions to manipulate stock visibility and public perception. The main victims appear to be individuals using automation tools for marketing or engagement campaigns.

Separately, GitLab identified several fake Python packages in PyPI that imitated popular Bittensor libraries. These packages contained code designed to steal cryptocurrency by hijacking staking functions. “By hiding malicious code within legitimate-looking staking functionality, the attackers exploited both the technical requirements and user psychology of routine blockchain operations,” GitLab‘s Vulnerability Research team stated.

- Advertisement -

In response to these incidents, PyPI announced that it will increase security by rejecting package uploads that could be used for so-called “ZIP confusion attacks.” This change is part of a broader effort to stop the spread of malicious software through third-party code libraries. PyPI will begin rejecting packages with mismatched ZIP archive contents starting February 1, 2026, following a six-month warning period.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Anthropic tightens AI safety after Claude hacks real systems

Claude accessed real systems after cyber testing environments exposed the models to the internet.Anthropic...

US, CrowdStrike disrupt Sality botnet in $150K crypto theft

US law enforcement and international partners disrupted the Sality botnet, a Malware network active...

21 Global Banks Unite to Launch Dollar Stablecoin by 2027

Twenty-one major banks, including Goldman Sachs, Bank of America, and Citi, are forming a...

StreamRat Android Trojan Hits 570K Meta Users via Fake Ads

Cybersecurity firm ThreatFabric uncovered a new Android banking trojan called StreamRat, spread via fake...

Trump $1 coin enters circulation, on sale today

The U.S. Mint has released a commemorative 2026 $1 coin featuring President Donald Trump,...

Must Read

5 Best Hacking eBooks for Beginners

In this article we present the 5 Best Hacking eBooks for beginners as ranked by our editorial teamWelcome to the world of hacking, where...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading