< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-18T16:50:00+05:30

16 Typosquatted RubyGems Packages Exploit Vulnerabilities to Steal Browser and Crypto Data

16 typosquatted RubyGems packages exploited vulnerable package name reuse and unvalidated author fields to deploy a Windows-based information stealer targeting browser credentials, crypto wallets, and Telegram data. The campaign used extconf.rb hooks to execute a Rust loader that fetched a Go-based payload, highlighting flaws in Ruby's package management design.

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.

OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below -

ubnuler ubnlder ri18nr reaker rakier orakw joxn

Read original article

*** END OF TRANSMISSION ***