StubMaker is a RubyGems supply-chain malware campaign and associated Windows information stealer delivered through typosquatted Ruby packages. The malicious gems abuse the extconf.rb native-extension installation hook to execute during gem installation, fingerprint the host, and on Windows retrieve and launch a multi-stage payload while making the build process appear legitimate by generating fake extension-build artifacts and stub scripts.
The Windows infection chain uses a Rust-based loader that decrypts and manually maps an embedded Go stealer entirely in memory. The embedded payload, internally identified as wincfg, is purpose-built for information theft. It targets Chromium-based browsers to extract saved passwords, cookies, session material, browsing history, extension storage, IndexedDB data, and payment-card information. It also includes functionality to recover Chromium Application-Bound Encryption keys from within browser processes through an embedded DLL, enabling theft from browsers protected by newer credential-encryption mechanisms.
Beyond browser theft, StubMaker searches for cryptocurrency wallet data across multiple desktop wallets and browser extensions, scans for seed phrases and validates candidate recovery phrases, and collects Telegram Desktop data. It also gathers host profiling information such as username, hostname, operating-system details, hardware characteristics, and public IP information. Collected data is packaged into an encrypted archive in memory, uploaded to a file-sharing service, and the resulting retrieval link is transmitted to attacker-controlled infrastructure.
The campaign has been associated with multiple RubyGems publisher accounts and repeated republication of malicious packages, including reuse of previously yanked gem names. Its targeting is centered on Windows developer systems that install malicious Ruby dependencies. No confirmed persistence mechanism has been established from the available reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A supply-chain malware campaign delivered through typosquatted RubyGems packages. During installation it fingerprints Windows developer hosts, downloads a Rust-based loader from GitHub Releases, and decrypts an embedded Go infostealer in memory for fileless execution. It steals browser credentials, cookies, cryptocurrency wallets, seed phrases, and Telegram data.
A Windows-based information stealer delivered via typosquatted RubyGems packages. It uses an extconf.rb installer hook to fetch a Rust-based loader that launches an embedded Go stealer. It steals browser credentials, payment card data, extension data, browsing history, cryptocurrency wallets and seed phrases, Telegram Desktop data, and system information, obtains the victim public IP, and exfiltrates the collected data as a password-protected ZIP via Gofile with the link sent to the operator over HTTP.
A multi-stage supply-chain malware campaign delivered via typosquatted RubyGems packages. During gem installation, a malicious extconf.rb hook beacons victim platform data, downloads a Rust loader on Windows, and executes it. The loader decrypts an embedded Go infostealer entirely in memory, which steals browser credentials, cookies, payment-card data, cryptocurrency wallets and seed phrases, Telegram Desktop data, and host information. It also uses an embedded DLL to recover Chromium Application-Bound Encryption keys, then uploads stolen data to Gofile and reports the link to an attacker webhook.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.