logo

StubMaker RubyGems Campaign Delivers a Windows Infostealer

ID: fc8602a6-3ba9-56e4-9f41-82c988ad106b

STIX ID: report--fc8602a6-3ba9-56e4-9f41-82c988ad106b

Feed Name: OpenSourceMalware Blog

Threat Score
80/100

Date Published: 2026-08-16

Date Updated: 2026-08-17

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

A supply-chain campaign named “StubMaker” published typosquatted RubyGems that run an installer hook to download a Rust Windows loader from GitHub; the loader decrypts an embedded Go infostealer (with an embedded ABE helper DLL) that harvests Chromium browser credentials, wallets/seed phrases, Telegram data, and host information, uploads an encrypted archive to Gofile, and posts the link to an attacker webhook — the report provides technical analysis, IOCs, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.