Find notable cyber news and cases, enriched with sources, timelines, and signals.

StubMaker RubyGems typosquatting campaign

Campaign
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

A RubyGems typosquatting campaign called StubMaker is delivering a Windows-based information stealer, putting package installers at risk of credential theft and crypto wallet compromise. The operation used 16 malicious gems and an extconf.rb install hook to launch a loader and payload chain. The packages were later yanked, but the campaign already exposed browser credentials, seed phrases, Telegram data, and payment card numbers to exfiltration.

Related Happenings

StubMaker Windows information stealer delivered via RubyGems

Malware Activity
H score30 First: 18.08.2026 14:40 Last: 18.08.2026 14:40 Sources 1

How related: This new malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data,

About this happening: The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...

Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users

Malware Activity
H score37 First: 03.08.2026 21:43 Last: 03.08.2026 21:43 Sources 1

About this happening: Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-...

Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect

Campaign
H score45 First: 27.07.2026 15:37 Last: 27.07.2026 15:37 Sources 1

About this happening: The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote...

SleeperGem RubyGems supply-chain campaign

Campaign
H score17 First: 20.07.2026 08:15 Last: 20.07.2026 08:15 Sources 1

About this happening: SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer m...

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

Timeline

  1. 18.08.2026 14:40 2 articles · 2h ago

    StubMaker campaign targets RubyGems users with malicious typosquats

    Initial Disclosure

    Cybersecurity researchers identified a typosquatting campaign targeting RubyGems users on August 15, 2026 and tracked it as StubMaker. The activity involved 16 malicious gems published by mod8rz41mje (aka Riley Miller) and rbq95bwt6q (aka Alex Davis), abused an extconf.rb install hook to fetch a 22 MB Rust-based loader from GitHub, and launched a Go-based stealer named wincfg that harvested browser credentials, cryptocurrency wallets, seed phrases, Telegram Desktop data, browsing history, extension data, payment card numbers, and system information before uploading password-protected ZIP archives to Gofile and sending the download link over unencrypted HTTP.

    Show sources