HomeSecurityMalicious RubyGems posing as Fastlane and stealing Telegram API data

Malicious RubyGems Posing as Fastlane and Stealing Telegram API Data

Two malicious RubyGems pretending to be popular Fastlane CI/CD redirect Telegram API requests to servers controlled by the attackers, with the aim of intercepting and stealing data.

See also: New xAI – Telegram collaboration: Grok integrates into Telegram

RubyGems Fastlane

RubyGems is the official package manager for the Ruby programming language and is used to distribute, install, and manage Ruby libraries (gems), similar to npm for JavaScript and PyPI for Python.

The malicious packages intercept sensitive data, such as chat IDs, message content, file attachments, proxy credentials, and even bot tokens, which can be used to hijack Telegram bots. The supply chain was discovered by Socket researchers, who alerted the Ruby developer community via a report.

The two packages that use typosquatting techniques to mimic Fastlane remain active in RubyGems with the following names:

  • fastlane-plugin-telegram-proxy: Published on May 30, 2025 and has 287 downloads
  • fastlane-plugin-proxy_teleram: Published on May 24, 2025 and has 133 downloads

Fastlane is a reliable open source plugin tool used to automate processes for mobile app developers . It helps manage code signing, create builds, submit apps to app stores, send notifications, and manage metadata.

fastlane -plugin-telegram is a legitimate plugin that allows Fastlane to send notifications via Telegram, using a bot that posts to a designated channel. This is especially useful for developers who need real-time updates on CI/CD processes from within workspace , so they can monitor key events without having to check dashboards.

See also: Gremlin Stealer: New info-stealer advertised on Telegram

Malicious RubyGems Posing as Fastlane and Stealing Telegram API Data
Malicious RubyGems Posing as Fastlane and Stealing Telegram API Data

The malicious gems discovered by Socket are almost identical to the original plugin, featuring the same public API, readme file, documentation, and basic functionality. The only – but crucial – difference is the replacement of the regular Telegram API endpoint (https://api.telegram.org/) with an endpoint controlled by the attackers via proxy ( rough-breeze-0c37[.]buidanhnam95[.]workers[.]dev ), in order to intercept (and very likely collect) sensitive information.

The data stolen includes the bot token, message data, uploaded files, and proxy credentials, if configured. The attacker has significant room for exploitation and persistence, as Telegram bot tokens remain valid until manually revoked by the victim.

Socket notes that the malicious gems' pages state that the proxy "does not store or modify your bot tokens." However, there is no way to verify this claim.

Developers who have installed the two malicious gems should immediately remove them and rebuild any mobile binaries produced after the installation date. Additionally, all bot tokens used with Fastlane should be renewed, as they are now considered compromised by RubyGems packages.

Socket also recommends exclusive access to domains like '*.workers[.]dev', unless there is an explicit need for access.

See also: Triton RAT leverages Telegram for remote access

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A related and critical point that arises from the above is the importance of security in the software supply chain. When libraries or plugins like those in RubyGems are compromised or maliciously crafted (typosquatting, malicious proxies, etc.), they can affect hundreds or even thousands of projects, without the end users immediately realizing it.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS