logo

60 RubyGems Packages Steal Data From Annoying Spammers

ID: 763e36c2-2b32-5d82-be6a-0c2ee1c4326c

STIX ID: report--763e36c2-2b32-5d82-be6a-0c2ee1c4326c

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-08-08

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A Korean threat actor operating as 'soonje' has been publishing malicious RubyGems since March 2023 that appear to provide marketing automation for gray-hat spam actors but also include Windows infostealers that exfiltrate usernames, passwords, and MAC addresses; 60 packages were identified with over 275,000 cumulative downloads and 16 remaining live, posing a supply-chain and credential-theft risk to users and potentially to downstream developers and services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.