Interestana
Home/News/16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
The Hacker News5 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have identified a sophisticated typosquatting campaign that has infiltrated the RubyGems package repository, a critical hub for the Ruby programming language's open-source ecosystem. The campaign, discovered on August 15, 2026, by the cybersecurity research group OpenSourceMalware, involves 16 malicious packages deliberately designed to mimic legitimate Ruby libraries. These packages are being tracked under the threat intelligence moniker "StubMaker." The primary objective of this malicious operation is to steal sensitive information from Windows-based systems, with a particular focus on harvesting browser credentials and cryptocurrency wallet data.

Typosquatting, a common cyberattack technique, involves registering domain names or, in this case, package names that are intentionally misspelled or slightly altered versions of popular, legitimate ones. The attackers exploit the human tendency to make typographical errors when typing or searching for software. Developers, often working under tight deadlines, may inadvertently download and integrate these malicious packages into their projects, believing them to be authentic dependencies. The RubyGems platform, widely used by developers worldwide to share and discover Ruby libraries and tools, presents an attractive target for such attacks due to its extensive reach within the developer community.

The identified malicious packages, including but not limited to "ubnuler," "ubnlder," "ri18nr," "reaker," "rakier," "orakw," and "joxn," are engineered to act as information stealers. Browser credentials, which encompass saved usernames and passwords for websites and online services, are a prime target as they can grant attackers unauthorized access to a multitude of accounts. Furthermore, the campaign specifically targets cryptocurrency wallets. These digital wallets store the private keys necessary to access and manage cryptocurrencies like Bitcoin or Ethereum, making them extremely valuable targets for financial theft. The attackers' focus on Windows users suggests a deliberate effort to exploit platform-specific vulnerabilities or functionalities for data exfiltration.

This discovery underscores a persistent and evolving threat within the open-source software supply chain. The reliance of modern software development on a vast network of third-party packages means that the integrity of these dependencies is paramount. A single compromised package can serve as an entry point for malware, potentially affecting not only the developer's immediate system but also any other projects or networks they interact with. OpenSourceMalware's ongoing monitoring of the "StubMaker" campaign is crucial for tracking its evolution, identifying any further malicious packages, and providing timely alerts to the Ruby developer community to mitigate the risks associated with this threat.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next