Fake RubyGems Packages Caught Stealing Browser Data and Crypto Wallets
Researchers at OpenSourceMalware have discovered a typosquatting campaign on RubyGems, the popular package repository for the Ruby programming language. The attackers published at least 16 packages with names deliberately similar to legitimate, widely used libraries, hoping developers would mistype or misidentify them during installation. Once installed on a Windows machine, the packages deploy malware dubbed StubMaker, which is designed to steal browser-stored credentials and cryptocurrency wallet data.
Typosquatting is a common tactic in software supply chain attacks, relying on small businesses and developers accidentally installing malicious packages that closely resemble trusted ones. Because RubyGems, like other open-source repositories, allows anyone to publish packages, attackers can slip malicious code into the ecosystem with minimal barriers. For small businesses that rely on developers or contractors using open-source tools, this kind of attack can lead to stolen passwords, compromised accounts, and financial loss through drained crypto wallets.
This incident is a reminder that supply chain risks extend beyond well-known software vendors to the open-source libraries powering everyday applications. Businesses using Ruby-based tools or contracting developers who do should ensure package names are verified carefully before installation, and that endpoint protection is in place to catch stealer-type malware.