Skip to content
DnsLister Forum

Where domain hunters compare notes

StubMaker RubyGems Campaign Delivers a Windows Infostealer

This is a classic supply chain attack targeting the Ruby ecosystem. The threat actors published malicious gems to RubyGems under the "StubMaker" campaign, which ultimately drops a Go-based infostealer on Windows systems.

Technical Breakdown: – Initial Access: Malicious RubyGems packages (likely typosquatting popular libraries) that execute a payload on gem install – Staging: The gem fingerprints the victim host (user, domain, hostname, OS info) and downloads a Windows loader binary – Loader: The downloaded loader decrypts and executes the final payload—an encrypted Go infostealer – Persistence & Exfiltration: The infostealer collects credentials, browser data, and system info, exfiltrating via C2 channels – IOCs: Check the source article for specific gem names, download URLs, and hashes—these are time-sensitive and should be pulled directly from the report

Defense: – Audit your Gemfile.lock for any recently added or updated gems from unknown publishers – Monitor for outbound connections to unusual IPs/domains from Ruby development environments – Consider running gem install in sandboxed or containerized environments for third-party dependencies – Implement runtime detection for processes spawning child processes (loader dropping infostealer) on Windows build agents

Source: https://opensourcemalware.com/blog/stubmaker-rubygems-windows-infostealer

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *