logo

Malicious RubyGems pose as Fastlane to steal Telegram API data

ID: dbccf455-1e5e-5433-9858-2fddeda56e7a

STIX ID: report--dbccf455-1e5e-5433-9858-2fddeda56e7a

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-06-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Two malicious RubyGems impersonating a legitimate fastlane Telegram plugin were discovered redirecting Telegram API traffic to an attacker-controlled proxy, allowing exfiltration of bot tokens, message content, uploaded files, and proxy credentials; Socket researchers reported the typosquatting supply-chain campaign, the packages remain live on RubyGems with measurable downloads, and impacted developers are advised to remove the gems and rotate tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.