Researchers disclosed a RubyGems supply-chain campaign that used 16 typosquatted and republished gems to infect Windows developer systems with the StubMaker information stealer. The operation reportedly exploited RubyGems package-name reuse and an unvalidated author field, letting attackers reclaim abandoned gem names, publish malicious versions, and make related packages appear unrelated. During installation, the malicious gems abused the extconf.rb hook to fingerprint hosts and retrieve a Rust-based loader from GitHub Releases.
The loader then decrypted and launched a Go-based infostealer in memory, enabling largely fileless execution and theft of browser credentials, cookies, payment card data, cryptocurrency wallets and seed phrases, Telegram Desktop data, browsing history, and system information. Stolen data was uploaded to Gofile, and the resulting download link was sent to the attackers over unencrypted HTTP. Reported indicators tied to the campaign include 193.70.34.101 and dresslee.com, along with multiple URLs and SHA-256 hashes published for detection; the malicious packages were later yanked from RubyGems.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
OpenSourceMalware reported that the same threat actor behind the RubyGems StubMaker campaign also ran a typosquatting campaign on npm, using the same command-and-control endpoint, GitHub-hosted Rust loader, and byte-identical Go infostealer. The analysis tied the two ecosystems together through shared infrastructure and matching payload hashes.
OpenSourceMalware discovered a new typosquatting campaign targeting RubyGems users and tracked it as StubMaker. The activity involved 16 malicious gems impersonating popular Ruby dependencies.
Researchers said a second RubyGems account later published 15 additional malicious gems, including a new version of brumdler, bringing the StubMaker campaign to at least 17 malicious gems. The campaign reportedly continued after takedowns by reclaiming yanked gem names through namespace reuse.
The 16 malicious RubyGems packages used in the StubMaker campaign were later removed from RubyGems. Researchers said the attackers had abused package-name reuse and owner changes to republish malicious versions under reclaimed gem names.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
opensourcemalware.com
Open sourcecommunity.gurucul.com
Open sourcethehackernews.com
Open sourceopensourcemalware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.