Tag: Steal Browser Credentials

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Business

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

A new typosquatting campaign that targets RubyGems users with a Windows-based information stealer has been discovered by cybersecurity researchers. The threat is being tracked under the name StubMaker by OpenSourceMalware, which found the activity on August 15, 2026. Below is a comprehensive list of all the packages released as part of the campaign: ubnuler ubnlder ri18nr reaker rakier orakw joxn ise18n ioe18n ie18u iai8n i1l8n i18om activesupmport brumdler brundlef According to security researcher Paul McCarty (also known as 6mile), this new malware gathers Telegram data, bitcoin wallets, browser credentials, and seed phrases. The malicious RubyGems packages all seem to be typosquats of well-known Ruby dependencies, but they're all ...
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
News

DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

A new operation has used the ClickFix social engineering technique to spread DeepLoad, a malware loader that was previously unreported. In a report shared with The Hacker News, ReliaQuest researchers Thassanai McCabe and Andrew Currie stated that while credential theft begins instantly and captures passwords and sessions even if the primary loader is blocked, it probably uses AI-assisted obfuscation and process injection to avoid static scanning. The attack chain begins with a ClickFix bait that deceives users into executing PowerShell commands by pasting the command into the Windows Run dialog under the guise of fixing a nonexistent problem. This then downloads and launches an obfuscated PowerShell loader using "mshta.exe," a valid Windows tool. For its part, it has been discove...