ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
HIGH Cybersecurity

StubMaker typosquats RubyGems packages to steal browser data and wallets

Source headline: 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

Researchers reported a typosquatting campaign targeting RubyGems users. The activity uses Windows-based information stealing to capture browser credentials and cryptocurrency wallets. The campaign is tracked as StubMaker by OpenSourceMalware, which flagged it on August 15, 2026. The report lists multiple lookalike RubyGems package names involved in the campaign. Running or installing these typosquatted packages could expose sensitive authentication and wallet material. Users should avoid installing the listed package names and remove any that were installed from RubyGems.

Recommended Action

Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#typosquatting #information-stealer #crypto-wallets #rubygems #browser-credentials
Original reporting The Hacker News 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Open original source