StubMaker is a Windows-focused supply-chain malware campaign and associated malware chain delivered through typosquatted RubyGems packages, and later linked to parallel npm activity by the same threat actor. The operation abused package installation hooks to execute malicious code during dependency installation on developer systems. In the RubyGems variant, malicious extconf.rb hooks fingerprinted the host, generated fake native-extension build artifacts so installation appeared successful, and on Windows downloaded and launched a Rust-based loader. That loader contained an embedded Go information-stealing payload, identified internally as wincfg, which was decrypted and manually mapped entirely in memory for fileless execution.
The malware chain is designed primarily for information theft from Windows hosts. The Go stealer targets Chromium-based browsers and can recover saved passwords, cookies and authenticated sessions, payment-card data, browsing-related data, extension storage, and IndexedDB content. It also targets cryptocurrency wallets and seed phrases, Telegram Desktop data, and general host information such as system characteristics and user context. The stealer includes functionality to bypass Chromium Application-Bound Encryption protections through an embedded DLL used to recover browser decryption material from within browser processes.
Collected data is assembled into a password-protected archive in memory and exfiltrated to attacker-controlled infrastructure. The campaign showed strong operational overlap across ecosystems, with the same loader and embedded stealer used in both RubyGems and npm typosquatting operations. Delivery was tied to malicious package-install hooks rather than conventional phishing, and the targeting pattern indicates a focus on developers and Windows development environments, including cases where Windows payload execution was reached from WSL contexts. No confirmed persistence mechanism has been established from the available facts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A supply-chain malware operation delivered through typosquatted RubyGems packages. It uses an install hook to fetch or launch a Windows Rust loader that decrypts an embedded Go infostealer in memory, stealing browser credentials, authenticated sessions, payment-card data, cryptocurrency wallets and seed phrases, Telegram data, and host information.
A supply-chain malware campaign delivered through typosquatted RubyGems packages. During installation it fingerprints Windows developer hosts, downloads a Rust-based loader from GitHub Releases, and decrypts an embedded Go infostealer in memory for fileless execution. It steals browser credentials, cookies, cryptocurrency wallets, seed phrases, and Telegram data.
A Windows-based information stealer delivered via typosquatted RubyGems packages. It uses an extconf.rb installer hook to fetch a Rust-based loader that launches an embedded Go stealer. It steals browser credentials, payment card data, extension data, browsing history, cryptocurrency wallets and seed phrases, Telegram Desktop data, and system information, obtains the victim public IP, and exfiltrates the collected data as a password-protected ZIP via Gofile with the link sent to the operator over HTTP.
A multi-stage supply-chain malware campaign delivered via typosquatted RubyGems packages. During gem installation, a malicious extconf.rb hook beacons victim platform data, downloads a Rust loader on Windows, and executes it. The loader decrypts an embedded Go infostealer entirely in memory, which steals browser credentials, cookies, payment-card data, cryptocurrency wallets and seed phrases, Telegram Desktop data, and host information. It also uses an embedded DLL to recover Chromium Application-Bound Encryption keys, then uploads stolen data to Gofile and reports the link to an attacker webhook.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.