SECURITYTHE HACKER NEWS
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers flagged a new typosquatting campaign targeting RubyGems users using a Windows-based information stealer. This campaign steals browser credentials and crypto wallets. OpenSourceMalware discovered the threat, which is currently being tracked under the moniker StubMaker.
Mentioned
Related Signal
Adjacent reporting
- Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
- Attackers Weaponize RubyGems for Data Dead Drops
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
- GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
- RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
- Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries