Skip to main content
VTechFusion Technologies
16 Typosquatted RubyGems Packages Caught Stealing Browser Credentials and Crypto Wallets
InsightsNewsIndustry & AI News
Industry & AI News5 min readAugust 19, 2026

16 Typosquatted RubyGems Packages Caught Stealing Browser Credentials and Crypto Wallets

VT

VTechFusion Team

VTechFusion Technologies

Cybersecurity researchers at OpenSourceMalware disclosed on August 15, 2026 a typosquatting campaign — tracked as StubMaker — using 16 malicious RubyGems packages to steal browser credentials, cryptocurrency wallet seed phrases, and Telegram session data from Windows developers.

How StubMaker Is Different From Ordinary Typosquatting

Most typosquatting attacks rely on a package name close enough to a popular library that a developer mistypes their way into installing it. StubMaker's name points to a more deliberate technique: manufacturing a fake build toolchain so the malicious install looks like a routine dependency step, rather than an obviously suspicious package — making it harder to catch in a quick visual review of a Gemfile or install log.

Part of a Wider Supply-Chain Pattern, Not an Isolated Incident

  • The RubyGems disclosure coincided with a separate campaign of 21 typosquatted npm packages that mimicked CLI binary names to deliver a minimal postinstall beacon
  • Both campaigns target the same weak point: developers trusting package names in dependency files without independently verifying the maintainer or install behavior
  • Neither requires a sophisticated exploit — both rely entirely on a developer's routine `install` command doing more than expected

For engineering teams, the actionable response isn't a one-time cleanup — it's routine dependency-provenance checks (verified maintainers, pinned versions, lockfile review) built into CI, not left to individual developer vigilance at install time.

Filed under:Industry & AI News
All News

Frequently Asked Questions

What does the StubMaker RubyGems campaign actually steal?

StubMaker steals browser credentials, cryptocurrency wallet seed phrases, and Telegram session data from Windows machines, using 16 typosquatted RubyGems packages disguised behind a fake build toolchain.

Is this an isolated RubyGems-only incident?

No. It coincided with a separate campaign of 21 typosquatted npm packages mimicking CLI binary names, indicating a broader pattern of supply-chain attacks against package registries developers trust by default.

Media & Press Enquiries

For editorial enquiries, expert commentary, or case study access.

Start Today

Ready to Build Something Great?

Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.