16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
A new typosquatting campaign that targets RubyGems users with a Windows-based information stealer has been discovered by cybersecurity researchers.
The threat is being tracked under the name StubMaker by OpenSourceMalware, which found the activity on August 15, 2026. Below is a comprehensive list of all the packages released as part of the campaign:
ubnuler
ubnlder
ri18nr
reaker
rakier
orakw
joxn
ise18n
ioe18n
ie18u
iai8n
i1l8n
i18om
activesupmport
brumdler
brundlef
According to security researcher Paul McCarty (also known as 6mile), this new malware gathers Telegram data, bitcoin wallets, browser credentials, and seed phrases. The malicious RubyGems packages all seem to be typosquats of well-known Ruby dependencies, but they're all ...










