16 Typosquatted RubyGems Packages Discovered to Steal Browser Credentials and Crypto Wallets

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybersecurity researchers have identified a new typosquatting campaign targeting RubyGems users, which involves a Windows-based information stealer known as StubMaker. Discovered by OpenSourceMalware on August 15, 2026, this campaign features 16 malicious packages that have since been removed from RubyGems. The packages include names such as ubnuler, ubnlder, and brumdler, among others.

According to reporting by The Hacker News, the malware is designed to harvest sensitive information, including browser credentials, cryptocurrency wallets, seed phrases, and Telegram data. Security researcher Paul McCarty noted that these packages are clumsy typos of popular Ruby dependencies, contrasting with more sophisticated typosquatting tactics seen in other campaigns.

The malicious gems were published by users identified as “mod8rz41mje” and “rbq95bwt6q.” In some instances, the threat actor exploited a known RubyGems behavior that allows anyone to claim a namespace once all versions of a gem have been yanked. This tactic enabled the attackers to republish malicious versions under the same package names.

Jenn Gile, co-founder of OpenSourceMalware, highlighted the effectiveness of the campaign, attributing it to Ruby’s design flaws, such as unvalidated author fields and package name reuse. This allowed the threat actor to create new owner accounts and publish additional malicious versions, reviving previously removed packages.

The attack utilizes an extconf.rb hook to execute a Rust-based loader from a GitHub release, which subsequently launches a Go-based stealer payload. This stealer is capable of extracting credentials from various Chromium-based browsers and collecting sensitive data, including browsing history and payment card information. The captured data is then uploaded to an external site in a password-protected ZIP archive.

This incident underscores the ongoing risks associated with typosquatting and the need for vigilance among developers using package management systems. Continuous monitoring and improved validation processes are essential to mitigate such threats.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Air Force plans to field 100 Massed Modular Aircraft drones by 2029

The United States Air Force is advancing its plans for the Massed Modular Aircraft (MMA) unmanned platform, with intentions to field 100 of these...

Surge in AI-Driven Vulnerabilities Leads to Record Number of CVEs, Straining Cybersecurity Resources

Recent developments in cybersecurity have revealed a significant surge in vulnerabilities driven by artificial intelligence (AI), leading to a record number of Common Vulnerabilities...

North Korean hackers steal over $10.5 million in cryptocurrency through ‘WaterPlum’ campaign targeting job seekers across 100 countries

North Korean hackers have reportedly stolen over $10.5 million in cryptocurrency through a campaign known as "WaterPlum," which targets job seekers across more than...

UAE Cyber Security Council and Fortinet Launch Internship Program for Emirati Students

The UAE Cyber Security Council (CSC) has partnered with Fortinet to launch a new cybersecurity internship programme aimed at equipping Emirati university students with...