HomeSecurityStubMaker: 16 typosquatted RubyGems packages steal data

StubMaker: 16 typosquatted RubyGems packages steal data

A new typosquatting is in the sights of cybersecurity researchers, with attackers using deceptive packages in RubyGems to distribute information-stealing malware on Windows systems. The activity was detected on August 15, 2026 by OpenSourceMalware, which tracks the threat under the name StubMaker.

Article Image: 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

A total of 16 malicious gems were identified, including ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn, ise18n, ioe18n, ie18u, iai8n, i1l8n, i18om, activesupmport, brumdler , and brundlef. These packages have now been removed from RubyGems, limiting their immediate availability.

Spelling mistakes that hide malware

The attackers' main technique was to create names that resemble well-known Ruby dependencies. However, unlike more sophisticated typosquatting campaigns that attempt to make malicious packages high in search results, this particular campaign relied primarily on obvious spelling errors.

See also: Malicious RubyGems and PyPI packages steal data

The gems were published by two accounts, named mod8rz41mje and rbq95bwt6q. Researchers linked the accounts to the names Riley Miller and Alex Davis. Choosing nearly identical names is a classic pitfall for developers who quickly type in a dependency or copy a name without carefully checking the actual creator.

Exploiting a vulnerability in RubyGems

The case is more interesting because of the way the perpetrators managed to recover package names. In at least two cases (brumdler and brundlef), a behavior in RubyGems that allows a namespace to be reclaimed when all versions of a gem have been retired was exploited.

The names in question had originally been used by a different account and were later transferred to the perpetrators' accounts. Thus, a name that had theoretically "died" could reappear with new, malicious content.

At the same time, the Author is not verified and is plain text. This means that the owner of a package can declare a different author, creating a false image of independent projects.

RubyGems - SecNews.gr

The dangerous hook of the installation

The real threat is triggered during installation. StubMaker exploits the extconf.rb, a mechanism that is legitimately used to configure and compile native extensions into Ruby packages.

In the malicious campaign, however, the hook is used to download a roughly 22 MB, written in Rust, from GitHub. The loader contains the main payload of the infostealer, named wincfg.

In this way, the installation of a seemingly innocent gem becomes the starting point of a complete infection chain. The user may not notice anything unusual, as the installation process appears to complete normally.

See also: Malicious RubyGems posing as Fastlane and stealing Telegram API data

What does StubMaker steal?

wincfg is designed to collect sensitive data in bulk . Among other things, it seeks credentials from Chromium-based browsers, such as Chrome, Edge, Brave, Opera, and Vivaldi, while attempting to bypass App-Bound Encryption , a mechanism introduced by Google to strengthen the browser's data protection.

The malware also collects browsing history, extension data, and payment card numbers. It also scans the system for cryptocurrency wallets and seed phrases, while targeting Telegram Desktop.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The collection is not limited to applications. The malware records system information and looks up the victim's public IP so that the attackers can gain a more complete picture of the infected machine.

The data ends up with the attackers

After collection, the stolen data is compressed into a protected ZIP file and uploaded to the Gofile service. The download link is then sent to the perpetrators via an unencrypted HTTP channel.

What is particularly interesting is that StubMaker does not need to perform any complex operations during the build phase. It essentially creates a fake build toolchain so that the installation looks normal, while the real malicious activity takes place in the installation hook.

Cursor at SpaceX enhances programming tools with artificial intelligence

Another warning message for developers

This specific campaign reminds us that the security of the software chain depends not only on a project's code, but also on the reliability of the dependencies that are installed daily.

See also: SleeperGem: Supply chain attack via RubyGems

For developers, careful verification of gem names, maintainers, versions, and the origin of each dependency is now essential. A single different letter can lead to malware installation, especially when the malicious package exploits legitimate installation mechanisms.

The StubMaker case ultimately shows that typosquatting doesn't have to be particularly sophisticated to be effective. All it takes is a typo and a package that looks enough like the original to allow a developer to unwittingly open the door to an infostealer.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS