16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Summary

Cybersecurity researchers have identified a typosquatting campaign on the RubyGems platform that distributes a Windows-based information stealer called StubMaker. The malicious packages were disguised as legitimate Ruby libraries and aimed to steal browser credentials and cryptocurrency wallet information.

IFF Assessment

FOE

This campaign represents a direct threat to users by stealing sensitive information and cryptocurrency, making it bad news for defenders.

Defender Context

This incident highlights the ongoing threat of typosquatting in software repositories, where attackers impersonate legitimate packages to distribute malware. Defenders should exercise extreme caution when installing new libraries, verifying package names meticulously and reviewing permissions and code behavior for any suspicious activity.

Read Full Story →