RubyGems.org dead drop for stolen credential data
Data Leak
Summary
Hide ▲
Show ▼
A malicious browser extension used RubyGems.org as a dead drop for stolen credential data, exposing 63 vault items with passwords, keys, and financial details. The uploaded material included plaintext passwords, SSH private keys, AWS credentials, crypto wallet seed phrases, and bank account details. Storing the loot in normal-looking package uploads increased the chance that the exposed secrets could be reused before detection.
Related Happenings
SleeperGem RubyGems supply-chain campaign
Campaign
H score17
First: 20.07.2026 08:15
Last: 20.07.2026 08:15
Sources 1
How related:
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
About this happening:
SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer m...
SleeperGem RubyGems supply-chain campaign
CampaignHow related: Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
About this happening: SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer m...
GemStuffer RubyGems data-exfiltration campaign
Campaign
H score29
First: 13.05.2026 11:08
Last: 13.05.2026 11:08
Sources 1
About this happening:
The GemStuffer campaign is abusing RubyGems as a data-exfiltration channel, with more than 150 gems used to stage scraped content. It targeted public-facing ModernGo...
GemStuffer RubyGems data-exfiltration campaign
CampaignAbout this happening: The GemStuffer campaign is abusing RubyGems as a data-exfiltration channel, with more than 150 gems used to stage scraped content. It targeted public-facing ModernGo...
Zara customer data leak exposing 197,400 people
Data Leak
H score78
First: 08.05.2026 13:42
Last: 08.05.2026 13:42
Sources 1
About this happening:
The Zara customer-data leak now exposes 197,400 people, creating privacy and phishing risk across multiple markets. The exposed records include unique email addresses,...
Zara customer data leak exposing 197,400 people
Data LeakAbout this happening: The Zara customer-data leak now exposes 197,400 people, creating privacy and phishing risk across multiple markets. The exposed records include unique email addresses,...
Panera Bread public leak of 5.1 million account records
Data Leak
H score79
First: 02.02.2026 15:46
Last: 02.02.2026 15:46
Sources 1
About this happening:
Panera Bread suffered a confirmed data leak after stolen account data was publicly posted on a dark web leak site, exposing 5.1 million accounts and raising immedi...
Panera Bread public leak of 5.1 million account records
Data LeakAbout this happening: Panera Bread suffered a confirmed data leak after stolen account data was publicly posted on a dark web leak site, exposing 5.1 million accounts and raising immedi...
Unauthenticated Moltbot instances expose configuration data and credentials
Data Leak
H score34
First: 28.01.2026 19:46
Last: 28.01.2026 19:46
Sources 1
About this happening:
Hundreds of unauthenticated Moltbot instances were found exposing configuration data, API keys, OAuth credentials, and private chat histories to unauthorized p...
Unauthenticated Moltbot instances expose configuration data and credentials
Data LeakAbout this happening: Hundreds of unauthenticated Moltbot instances were found exposing configuration data, API keys, OAuth credentials, and private chat histories to unauthorized p...
Timeline
-
20.07.2026 08:15 2 articles · 17h ago
Malicious browser extension uses RubyGems.org as a dead drop for stolen secrets
Initial DisclosureA malicious browser extension harvested credentials through a locally accessible API, packaged the data into valid .gem files in the browser using JavaScript and standard Web APIs, and uploaded the packages to RubyGems.org as a dead drop. The haul included plaintext passwords, SSH private keys, AWS credentials, crypto wallet seed phrases, Social Security numbers, credit card numbers, and bank account details across 63 vault items.
Show sources
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — thehackernews.com — 20.07.2026 08:15
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — thehackernews.com — 20.07.2026 08:15