HackMyIP
← Back to News
2026-08-18 The Hacker News

StubMaker Typosquat Campaign Steals Browser and Crypto Data via RubyGems

Supply ChainMalwareThreat Intel

Cybersecurity researchers at OpenSourceMalware have uncovered a typosquatting campaign targeting the RubyGems ecosystem with a Windows-based information stealer dubbed StubMaker. First observed on August 15, 2026, the campaign involves 16 malicious packages—ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn, ise18n, ioe18n, ie18u, iai8n, i1l8n, i18om, activesupmport, brumdler, and brundlef—each mimicking popular Ruby dependencies with clumsy name variations. The malware harvests browser credentials, cryptocurrency wallet data, seed phrases, and Telegram information, according to researcher Paul McCarty (aka 6mile). Compromised users should immediately verify exposure using an email breach checker and run any recovered passwords through a password checker to gauge reuse risk.

The malicious gems were published by two accounts—"mod8rz41mje" (linked to Riley Miller) and "rbq95bwt6q" (linked to Alex Davis)—and have since been yanked from RubyGems. OpenSourceMalware co-founder Jenn Gile noted that the campaign became more effective due to Ruby's package-namespace reuse behavior and an unvalidated author field. In the cases of brumdler and brundlef, the threat actors reclaimed gem names originally published by "gemlewqqhu1" (Taylor Moore) after they were yanked, then republished malicious versions under the same package names while assigning distinct author labels to obscure the common origin.

The attack chain exploits Ruby's native extension hook, "extconf.rb," which executes automatically during gem installation—analogous to npm lifecycle scripts. StubMaker uses this hook to fetch a 22 MB Rust-based loader from a GitHub release associated with the account "github[.]com/bebraz1," now offline. The loader subsequently deploys a Go-based stealer ("wincfg") containing an embedded DLL payload designed to exfiltrate sensitive data from infected Windows hosts. Developers auditing their environments for residual compromise should inspect installed gems, verify package signatures, and use a port scanner to identify suspicious outbound connections tied to stealer infrastructure.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →