Typosquat RubyGems Stealer Hits Dev Machines

The Hacker News · Medium sophistication
Last updated August 19, 2026

Researchers found 16 look‑alike (typosquatted) RubyGems packages that trick developers into installing a Windows information stealer. The malicious gems run code automatically during installation, pull down additional malware, and then steal browser logins and crypto wallet data before uploading it to attacker-controlled infrastructure.

How the attack worked

Researchers identified 16 typosquatted RubyGems packages designed to look like popular Ruby dependencies. Developers who installed one of these look-alike gems, often due to a simple misspelling, triggered malicious code automatically through Ruby's extconf.rb install hook. This hook acted as a conduit to fetch a 22 MB Rust-based loader from a GitHub release, which in turn launched a Go-based stealer payload on the victim's Windows machine. The stealer harvested browser credentials, cryptocurrency wallet and seed phrase data, and Telegram data, then packaged it into a password-protected ZIP uploaded to Gofile. The resulting download link was sent to the attacker over unencrypted HTTP.

Why it succeeded

The campaign relied on a combination of naming deception and platform behavior that developers may not fully anticipate. Because gem names were near-matches of well-known dependencies, they were easy to overlook during quick installs. The install-time code execution behavior, similar to lifecycle hooks in other package ecosystems, meant that simply installing a package (not even running it) was enough to trigger compromise. In at least two cases, the attacker also took advantage of a RubyGems platform behavior that makes a namespace available for reclaiming once all versions of a gem have been yanked, allowing a malicious actor to republish under a name that looked familiar and previously legitimate.

What to watch for

  • Package names that are near-identical misspellings of popular dependencies
  • Installations that unexpectedly download large external binaries or loaders
  • Gem names that were previously yanked and have since reappeared under new ownership
  • Author metadata that varies gem to gem or does not match the listed owner, since this field is unvalidated plaintext

Building resistance

Security and engineering teams can reduce exposure by training developers to verify exact package names before installing and treating look-alike names as a high-risk signal. Because install-time execution can run without any additional user action, download and build steps triggered during package installation should be reviewed and monitored. Teams should also add governance checks around package ownership changes and republished or previously yanked names before allowing them into builds. Finally, developers should be reminded that package metadata, including the Author field, is not validated and cannot be used alone to confirm a package's legitimacy.

Key findings

  • A typosquatting campaign published 16 malicious RubyGems packages that installed a Windows info stealer.
  • The malware steals browser credentials, crypto wallets/seed phrases, and Telegram data.
  • The malicious behavior triggers automatically during gem installation via Ruby’s extconf.rb hook.
  • The installer pulls a Rust-based loader from a GitHub release, which launches a Go-based stealer payload.
  • Stolen data is uploaded as a password-protected ZIP to Gofile; the resulting link is sent to the actor via unencrypted HTTP.

Who’s being targeted

  • Commonly targeted roles: Developers, DevOps, Build/Release engineers, Open-source program office (OSPO), Security engineering (AppSec).
  • Affected industries: Software development, Technology, Open-source maintainers and users.
  • Attack channels: website.
  • Impersonated: A legitimate Ruby dependency on RubyGems (look-alike/typosquat of a popular gem), A previously legitimate gem that was yanked and later reclaimed.

Red flags to watch for

  • Package name is a misspelling/near-match of a well-known dependency
  • Package ownership/author details look inconsistent or recently changed
  • Install unexpectedly downloads large external binaries during installation
  • Gem name was previously yanked but later republished by a different owner
  • Author field varies and does not match the owner (can be unvalidated text)
  • Registry history shows unusual churn in ownership/versions
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the malicious RubyGems packages infect developer machines?

The malicious behavior triggered automatically during gem installation via Ruby's extconf.rb hook, which pulled a Rust-based loader from a GitHub release that then launched a Go-based stealer payload.

What data did the RubyGems stealer campaign steal?

The malware stole browser credentials, cryptocurrency wallets and seed phrases, and Telegram data, then uploaded it as a password-protected ZIP to Gofile.

Can a previously deleted (yanked) gem name be reused by attackers?

Yes. RubyGems allows a namespace to be claimed by anyone once all versions of a gem have been yanked, and the threat actor exploited this to republish malicious versions under familiar package names.

Can developers trust the Author field on a RubyGems package?

No, the Author field is an unvalidated plaintext field that does not have to match the actual package Owner, so it should not be treated as proof of legitimacy.

Read the video transcript

You typo one gem name, boom, your dev box is leaking browser logins and crypto wallets. These typosquatted RubyGems run extconf dot rb during install, quietly pulling a 22 meg Rust loader from GitHub that launches a Go info stealer. The stealer zips up your browser passwords, seed phrases, and Telegram data, uploads it to Gofile, then sends a plain HTTP link out, no alerts, just gone. Your move: before installing or updating a gem, pause and verify the exact name and owner in RubyGems, if it’s a near‑match or newly owned, don’t ship it.

Categories

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
Trojanized Zoom/Webex Installers Spread Starland RAT

Trojanized Zoom/Webex Installers Spread Starland RAT

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software (like Webex, Zoom, and MobaXterm). Once a victim runs the fake installer, a custom remote-access tool (“Starland RAT”) is installed and used to…

July 16, 2026
AsyncAPI npm Packages Poisoned via Malicious PR

AsyncAPI npm Packages Poisoned via Malicious PR

Attackers compromised the @asyncapi npm organization by abusing a misconfigured GitHub Actions workflow, then republished multiple AsyncAPI-related packages with a hidden loader. The malware ran automatically when the poisoned packages were imported (not during install), pulled a second-stage…

July 16, 2026
Spoofed Portal Drops APT36 Backdoor on Telecoms

Spoofed Portal Drops APT36 Backdoor on Telecoms

The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to…

August 18, 2026