Ethical Hacking News
Unleashing the Shadow of Malware: A Decisive Look into the Typosquatting Campaign Targeting RubyGems Users. A recent cyber attack, dubbed "StubMaker," has left millions of browsers and cryptocurrency wallets exposed to malicious threats. The attack, which was first reported on August 15, 2026, highlights the vulnerability of software supply chains and the need for better security measures to protect against such threats.
The "StubMaker" cyber attack has exposed millions of browsers and cryptocurrency wallets to malicious threats.A malicious campaign published 16 typosquatted RubyGems packages, stealing sensitive data from unsuspecting users.The attack chain uses a 22 MB Rust-based loader to fetch a Go-based stealer payload, which extracts credentials from Chromium-based web browsers.The malware collects extension data, browsing history, payment card numbers, and other sensitive information.The stolen data is uploaded to Gofile in a password-protected ZIP archive and sent to the threat actor via an unencrypted HTTP channel.The attack highlights the vulnerability of software supply chains and the need for better security measures to protect against such threats.
A recent cyber attack, dubbed "StubMaker," has highlighted the vulnerability of RubyGems users, leaving millions of browsers and cryptocurrency wallets exposed to malicious threats. The malicious campaign, which has garnered significant attention in the cybersecurity community, has resulted in the theft of sensitive data from unsuspecting users.
According to a study by OpenSourceMalware, a group of cybersecurity researchers, the campaign involved the publication of 16 typosquatted RubyGems packages on the RubyGems repository. The malicious packages, which were created by two users named "mod8rz41mje" and "rbq95bwt6q," were designed to steal browser credentials, cryptocurrency wallets, seed phrases, and Telegram data from users.
The attack chain, which is attributed to the "StubMaker" malware, begins with the publication of a malicious RubyGems package. Upon installation, the package triggers an "extconf.rb" hook, which, in turn, fetches a 22 MB Rust-based loader from a GitHub release. The loader then launches a Go-based stealer payload, which incorporates a DLL payload that extracts credentials from Chromium-based web browsers.
The malicious code also collects extension data, browsing history, and payment card numbers; searches for cryptocurrency wallets and seed phrases; extracts Telegram Desktop data; gathers system information; and makes an external request to "api.ipify[.]org" to obtain the victim's public IP address.
Once the relevant data is captured, it is uploaded to Gofile in the form of a password-protected ZIP archive and the resulting download link is sent to the threat actor ("dresslee.com") over an unencrypted HTTP channel. The malware does not generate any builds or code; instead, it creates a fake build toolchain to make a malicious install look like a routine one.
The campaign, which was first reported on August 15, 2026, has been linked to two software supply chain campaigns targeting npm, which involved the typosquating of CLI binary names exposed by Google's scoped packages to deliver a minimal postinstall beacon. The npm campaigns, which were discovered earlier this year, exploited a vulnerability in the npm package manager to deliver malicious code to unsuspecting users.
The attack highlights the vulnerability of software supply chains and the need for better security measures to protect against such threats. The incident also underscores the importance of proper maintenance and updates of software packages to prevent such attacks.
In conclusion, the "StubMaker" campaign serves as a warning to software developers and users to be vigilant in protecting against malicious threats. The attack highlights the need for improved security measures, including better software supply chain management and regular updates of software packages.
Related Information:
https://www.ethicalhackingnews.com/articles/Unleashing-the-Shadow-of-Malware-A-Decisive-Look-into-the-Typosquatting-Campaign-Targeting-RubyGems-Users-ehn.shtml
https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html
https://thehackernews.com/2025/08/rubygems-pypi-hit-by-malicious-packages.html
Published: Tue Aug 18 07:20:08 2026 by llama3.2 3B Q4_K_M