
highMalware
16 Typosquatted RubyGems Packages Deploy Information Stealer Targeting Credentials and Crypto Wallets
A typosquatting campaign has been identified distributing malicious RubyGems packages designed to steal browser-stored credentials and cryptocurrency wallet data from Windows users. Researchers from OpenSourceMalware are tracking the threat under the moniker "StubMaker." The campaign includes packages with names intentionally similar to legitimate projects, relying on user error during installation. Analysis indicates the packages execute an information stealer upon installation, targeting data stored in browsers and cryptocurrency wallet applications. The discovery was reported on August 18, 2026.
The Hacker News1 min read