BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

StubMaker: 16 typosquat RubyGems packages steal data

StubMaker typosquatting campaign steals credentials via malicious RubyGems packages.

  • Cybersecurity researchers have discovered a new typosquatting campaign, tracked as StubMaker, targeting RubyGems users with a Windows-based information stealer.
  • The 16 malicious gem packages were published by two accounts and have since been yanked; however, threat actors exploited a RubyGems namespace reuse flaw to republish packages.
  • The malware targets browser credentials, cryptocurrency wallets, seed phrases, and Telegram data via a multi-stage attack using Rust and Go-based payloads.

Cybersecurity researchers have flagged a new typosquatting campaign, tracked as StubMaker, targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, identified 16 malicious gems published by users “mod8rz41mje” and “rbq95bwt6q.”

- Advertisement -

“This new malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data,” security researcher Paul McCarty said. All packages appear to be clumsy typosquats of popular Ruby dependencies.

In at least two cases – brumdler and brundlef – the threat actor exploited a known RubyGems behavior allowing namespace reuse after packages are yanked. Jenn Gile, co-founder of OpenSourceMalware, told The Hacker News that the campaign became more effective because of Ruby’s “poor design choices” via package name reuse and an unvalidated author field.

“When one of the malicious gems was yanked, the threat actor was able to spin up a new owner account and publish a new malicious version under the same package name,” Gile said. “What should have been forever dead was revived to compromise more people.”

The attack chain uses an “extconf.rb” hook to trigger execution upon gem installation. This hook acts as a conduit to fetch a 22 MB Rust-based loader from a GitHub release, which then launches a Go-based stealer payload.

- Advertisement -

The stealer extracts credentials from Chromium-based browsers by circumventing app-bound encryption protections. It also collects cryptocurrency wallets and seed phrases, extracts Telegram Desktop data, and uploads the stolen information to Gofile as a password-protected ZIP archive.

“StubMaker doesn’t build anything — it generates a Makefile with empty targets, plus Unix and Windows stub scripts that do nothing but return success,” McCarty explained. The discovery coincides with two additional software supply chain campaigns targeting npm, including one cluster that typosquatted CLI binary names exposed by Google’s scoped packages.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Cronos confirmed $9.19 million left its blockchain before a network rollback reversed a crypto...

Presearch Shut Down and Left Me With 60 Cents. Their Own Filings Show Why.

I bought €100 of PRE about two and a half years ago. I was...

Nvidia CEO touts GPUs as revenue-generating assets

NVIDIA CEO Jensen Huang says the company's GPUs are a “productive, revenue-generating asset” as...

White-hat hackers return 3,400 BTC to Liquid after patch

White-hat Hackers returned 3,400 Bitcoin (~$270 million) to the Liquid Federation wallet.The original withdrawal...

UK FCA may lift ban on prediction markets for retail

The UK's Financial Conduct Authority is reportedly weighing whether to lift its 2019 ban...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading