Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Typosquatting Campaign Targets RubyGems Users’ Data

Typosquatting Campaign Targets RubyGems Users’ Data

Posted on August 18, 2026 By CWS

Cybersecurity experts have identified a new typosquatting campaign posing a significant risk to RubyGems users. The campaign, uncovered by OpenSourceMalware on August 15, 2026, involves a Windows-based information stealer that compromises user data.

Discovery and Impact

Dubbed StubMaker, this malicious campaign has been tracked by security researchers and involves a series of packages with deceptive names. These include ‘ubnuler’, ‘ri18nr’, and ‘brumdler’, among others. The campaign aims to extract sensitive information such as browser credentials, cryptocurrency wallets, and Telegram data.

Security researcher Paul McCarty, also known as 6mile, noted that the affected RubyGems packages are poorly disguised typosquats of popular Ruby dependencies. Unlike sophisticated SEO-driven typosquats observed in other threats, these packages are easily identifiable due to their clumsy naming.

Execution and Exploitation

The malicious packages, published by users ‘mod8rz41mje’ and ‘rbq95bwt6q’, exploit a known RubyGems vulnerability. This flaw allows the re-registration of package names once previous versions are removed. Notably, ‘brumdler’ and ‘brundlef’ were originally published by another user before being co-opted by the attackers.

Jenn Gile, co-founder of OpenSourceMalware, highlighted Ruby’s design flaws that facilitate such attacks. The ability to reuse package names and the unregulated ‘Author’ field in RubyGems allowed the attackers to masquerade as different entities while operating under the same account.

Technical Aspects and Broader Implications

The attack employs the ‘extconf.rb’ hook within the Ruby environment, which functions similarly to npm’s lifecycle hooks. This hook triggers the download and execution of a Rust-based loader, which subsequently initiates a Go-based stealer payload. The stealer targets various data sources, including browsers and cryptocurrency wallets, and uploads the harvested data to a remote server.

This incident coincides with other software supply chain threats, such as npm-focused campaigns. These include a set of npm packages that mimic CLI binary names to deliver beacons and Baileys npm forks that engage in malicious activities like hijacking WhatsApp accounts.

Security firm SafeDep has reported that these npm threats exploit gaps in dependency management, underscoring the need for continuous monitoring and improved security practices in software package registries.

As the landscape of software supply chain attacks evolves, vigilance and robust security measures are critical to safeguarding user data and maintaining the integrity of open-source ecosystems.

The Hacker News Tags:browser credentials, cryptocurrency theft, Cybersecurity, data breach, information stealer, malicious packages, Malware, NPM, online security, open source security, package names, RubyGems, software supply chain, Threat Actors, typosquatting

Post navigation

Previous Post: Critical VMware Flaw Exploited for Full Infrastructure Control
Next Post: Xpander Secures $7.5M for AI Platform Expansion

Related Posts

Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing Filters Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing Filters The Hacker News
SEC Files Charges Over  Million Crypto Scam Using Fake AI-Themed Investment Tips SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips The Hacker News
Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict The Hacker News
Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager The Hacker News
Critical Magento RCE Flaw Added to CISA Vulnerability List Critical Magento RCE Flaw Added to CISA Vulnerability List The Hacker News
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Crypto Scam Targets Phone Numbers to Find Victims
  • Xpander Secures $7.5M for AI Platform Expansion
  • Typosquatting Campaign Targets RubyGems Users’ Data
  • Critical VMware Flaw Exploited for Full Infrastructure Control
  • WordPress Plugin Flaw Puts 300,000 Sites at Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Crypto Scam Targets Phone Numbers to Find Victims
  • Xpander Secures $7.5M for AI Platform Expansion
  • Typosquatting Campaign Targets RubyGems Users’ Data
  • Critical VMware Flaw Exploited for Full Infrastructure Control
  • WordPress Plugin Flaw Puts 300,000 Sites at Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark