StubMaker Malware Campaign Hit RubyGems and npm With the Same Windows Infostealer
Researchers found one threat actor ran typosquatting campaigns on RubyGems and npm days apart, sharing an identical Rust loader and Go infostealer.
Editor's Note ·
- Correction:
- The article quotes OpenSourceMalware as saying 'researchers discovered newly-published RubyGems packages deploying multi-stage Windows infostealer malware.' The source actually states: 'On August 15, 2026, we discovered newly-published RubyGems packages that installs a multi-stage Windows infostealer malware.' The quoted passage paraphrases rather than reproduces the source verbatim.
- Correction:
- The article's 'What We Don't Know' section states that 'the full list of all 37 npm package names and all associated account details has not been fully published.' This is incorrect: OpenSourceMalware's August 19, 2026 write-up publishes a complete table of all 37 npm package names, their npm publisher accounts, and first/last-published timestamps, and separately lists all five npm account names with their registered Gmail addresses. The Hacker News also independently lists all 37 package names by name.
Overview
A single threat actor ran two separate typosquatting campaigns against RubyGems and npm using an identical malware payload, according to OpenSourceMalware, which said the RubyGems and npm installers “beacon to the same C2 endpoint” and “pull a Windows loader from the same GitHub release,” with the loader and its embedded infostealer being “byte-for-byte identical between the two campaigns (matching SHA-256 hashes, not just similar behavior).” The campaign, tracked as StubMaker, was first spotted on RubyGems and then found to have quietly expanded into npm days later, according to OpenSourceMalware and The Hacker News.
What We Know
Ruby security researchers discovered the RubyGems side of the campaign on August 15, 2026, when “researchers discovered newly-published RubyGems packages deploying multi-stage Windows infostealer malware,” according to OpenSourceMalware. The campaign involved 16 malicious gem names spread across three RubyGems accounts, typosquatting the popular bundler, i18n, rake, and activesupport libraries, according to OpenSourceMalware.
The RubyGems installer worked by abusing extconf.rb, the file RubyGems expects native-extension gems to use to configure and build C code during installation. “StubMaker doesn’t build anything” in a real sense — the researchers named the campaign after make_stub and make_stub.bat, describing them as “the fake compiler stand-ins the installer writes to disk,” so that “the extension phase reports a clean build while the real work … happens in the installer hook itself,” according to OpenSourceMalware. That hook downloaded a 22 MB Rust-based loader from a GitHub release, which in turn carried an embedded Go-language infostealer that decrypted and ran entirely in memory, according to OpenSourceMalware. The stealer targeted Chromium-based browsers to pull saved credentials, cookies and session tokens, and payment-card data, along with cryptocurrency wallets, seed phrases, and Telegram Desktop data, and exfiltrated everything through Gofile to a webhook, according to OpenSourceMalware.
The attackers also exploited a quirk of RubyGems’ package metadata. “In Ruby, authors isn’t a verified identity,” the researchers wrote. “It’s a plain-text field set in the gem’s .gemspec before it’s built, no different from the version number or description,” according to OpenSourceMalware. That let the operator resurface after a takedown: one package name, brumdler, was pulled once and then republished under a second account, since “once all versions of a gem are yanked, its namespace opens up for any account to claim with a new push — the original owner has no special reclaim right,” according to OpenSourceMalware. The 16 gems accumulated hundreds of downloads before removal, according to OpenSourceMalware.
Security researcher Paul McCarty said the RubyGems typosquats were unusually crude. “All of the malicious RubyGems packages appear to be typosquats of popular Ruby dependencies, but rather than the clever SEO-fueled typosquats we’ve seen from other threat actors … they’re all clumsy typos,” McCarty said, according to The Hacker News.
On August 19, 2026, OpenSourceMalware said it had cross-checked payloads from a separate npm campaign against its RubyGems findings and confirmed the two were run by the same operator. The npm side, originally documented by researcher group OpenHack, involved 37 malicious packages typosquatting popular libraries including chalk, commander, lodash, typescript, react, and axios, according to OpenSourceMalware. Those packages “went live in an eight-minute burst starting 02:48 UTC on August 16, and npm had pulled every one of them down by 04:12 UTC,” spread across five npm accounts each registered with a distinct, generic-looking Gmail address, according to OpenSourceMalware.
Rather than faking a build process, the npm packages used postinstall.js, “a standard, documented lifecycle hook npm runs automatically, no pretense required,” according to OpenSourceMalware. The npm installer swapped the RubyGems version’s Base64-encoded loader URL for repeated-key XOR obfuscation using a hardcoded key, stf2026 — what the researchers called “a deliberate rewrite for the new platform rather than a copy-paste of the Ruby approach.” But both installers “beacon to the same C2 endpoint” at 193.70.34.101:20099 and “pull a Windows loader from the same GitHub release,” according to OpenSourceMalware.
Jenn Gile, co-founder of OpenSourceMalware, said the shared infrastructure pointed to a single operator running two parallel campaigns. “This was one threat actor running two typosquatting fronts against two package ecosystems, sharing a single payload and a single C2 backend,” Gile said, according to The Hacker News, a conclusion echoed in OpenSourceMalware’s own write-up, which called the RubyGems and npm campaigns “two independent typosquatting campaigns using different install hooks” delivering “the same Rust loader and the same Go infostealer.”
The two campaigns also unfolded on different schedules. “RubyGems’ pattern was sequential and single-point-of-failure,” Gile said, according to The Hacker News — the operator’s first two RubyGems packages, brumdler and brundlef, were taken down, then the operator returned under a new account with 15 more gems roughly two days later. npm, by contrast, saw all 37 packages published in parallel from five separate accounts within an eight-minute window, “with no visible adaptation cycle and no second wave yet identified,” according to OpenSourceMalware.
What We Don’t Know
OpenSourceMalware has not publicly attributed the campaign to a specific named threat actor or group beyond describing it as a single operator. The full list of all 37 npm package names and all associated account details has not been fully published, and it is not yet confirmed whether additional ecosystems beyond RubyGems and npm were targeted using the same infrastructure.
Analysis
OpenSourceMalware framed the dual-ecosystem approach as a blind spot for organizations that run both Ruby and Node.js stacks: “this operation had two independent paths into you, sharing nothing but infrastructure: the same beacon IP, the same GitHub-hosted loader, the same Go infostealer,” the researchers wrote, warning that “a team watching Gemfile.lock and a team watching package-lock.json could each investigate a typosquat campaign in isolation and never realize it’s the same actor hitting them from two directions,” according to OpenSourceMalware. The researchers recommended blocking the shared command-and-control address and exfiltration domain at the network layer as a more durable defense than typosquat-name blocklisting alone, “which has to be rebuilt every time the operator picks new typosquat targets,” according to OpenSourceMalware.