Windows Infostealer Hits npm and Ruby
ID: b4d6267c-6e37-54ad-a58a-15ccd92260b9
STIX ID: report--b4d6267c-6e37-54ad-a58a-15ccd92260b9
Feed Name: OpenSourceMalware Blog
Date Published: 2026-08-19
Date Updated: 2026-08-19
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
A single threat actor ran parallel typosquatting campaigns on npm (37 packages) and RubyGems (16 packages) delivering an identical Rust loader and embedded Go infostealer that decrypts in memory; the operation exfiltrates browser credentials, wallets, Telegram data and host information to Gofile and reports to a webhook at dresslee.com, with confirmed network and file IOCs (IP 193.70.34.101:20099, GitHub release URL, and matching SHA-256 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
