Attackers Impersonate Ruby Packages to Steal Sensitive Telegram Data
ID: 7877b93e-e61c-5174-93e1-bcf3094c975b
STIX ID: report--7877b93e-e61c-5174-93e1-bcf3094c975b
Feed Name: Dark Reading
Date Published: 2025-06-04
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Malicious RubyGems posing as fastlane Telegram proxy plugins were uploaded to RubyGems and modified a single network endpoint so that all Telegram API calls are relayed through attacker-controlled servers. The relay returns valid Telegram responses while exfiltrating bot tokens, chat IDs, messages, attachments and proxy credentials. The packages surfaced May 24 and May 30, 2025 (timed with Vietnam's Telegram block), and although likely aimed at developers seeking Telegram workarounds, the gems contain no geofencing and can compromise any environment that installs them; recommended mitigations include removing the gems, locking dependencies, rotating tokens, rebuilding binaries produced after May 30, and implementing API security controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
