logo

Windows Infostealer Hits npm and Ruby

ID: b4d6267c-6e37-54ad-a58a-15ccd92260b9

STIX ID: report--b4d6267c-6e37-54ad-a58a-15ccd92260b9

Feed Name: OpenSourceMalware Blog

Threat Score
78/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e

...
...

A single threat actor ran parallel typosquatting campaigns on npm (37 packages) and RubyGems (16 packages) delivering an identical Rust loader and embedded Go infostealer that decrypts in memory; the operation exfiltrates browser credentials, wallets, Telegram data and host information to Gofile and reports to a webhook at dresslee.com, with confirmed network and file IOCs (IP 193.70.34.101:20099, GitHub release URL, and matching SHA-256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.