Find notable cyber news and cases, enriched with sources, timelines, and signals.

StubMaker Windows information stealer delivered via RubyGems

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-wallet data at risk on infected endpoints. The payload also targets seed phrases, Telegram data, and payment card numbers, expanding the theft surface beyond a single credential set. Researchers found the activity on August 15, 2026, and the malicious packages were later removed from RubyGems.

Related Happenings

StubMaker RubyGems typosquatting campaign

Campaign
H score42 First: 18.08.2026 14:40 Last: 18.08.2026 14:40 Sources 1

How related: Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.

About this happening: A RubyGems typosquatting campaign called StubMaker is delivering a Windows-based information stealer, putting package installers at risk of credential theft and ...

SleeperGem RubyGems supply-chain campaign

Campaign
H score17 First: 20.07.2026 08:15 Last: 20.07.2026 08:15 Sources 1

About this happening: SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer m...

BusySnake Stealer Windows information-theft activity

Malware Activity
H score30 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The BusySnake Stealer malware is being used against Windows systems to steal browser cookies, passwords, documents, screenshots, wallet files, and Telegram data, increasin...

Millenium RAT Windows malware activity and native C++ rewrite

Malware Activity
H score62 First: 29.06.2026 17:30 Last: 29.06.2026 17:30 Sources 1

About this happening: The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...

Windows cryptocurrency clipper malware using USB LNK worming and Tor C2

Malware Activity
H score29 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...

Timeline

  1. 18.08.2026 14:40 2 articles · 2h ago

    StubMaker typosquatting campaign targets RubyGems users with a Windows stealer

    Initial Disclosure

    OpenSourceMalware identified a typosquatting campaign on RubyGems called StubMaker that used 16 malicious gems published under accounts including mod8rz41mje and rbq95bwt6q to target RubyGems users with a Windows-based information stealer. The packages were later yanked from RubyGems, and researchers said the campaign abused package-name reuse, extconf.rb execution during gem install, and a GitHub-hosted loader to steal browser credentials, cryptocurrency wallets, seed phrases, Telegram data, extension data, browsing history, and payment card numbers before exfiltrating the data through Gofile and unencrypted HTTP.

    Show sources