StubMaker RubyGems Campaign Delivers a Windows Infostealer

    Date: 08/18/2026

    Severity: High

    Summary

    The StubMaker campaign is a RubyGems supply chain attack that distributed typosquatted Ruby packages containing malicious extconf.rb installer hooks to compromise Windows developer systems. During installation, the packages fingerprint the host, download a Rust-based loader from GitHub Releases, and decrypt an embedded Go infostealer entirely in memory for fileless execution. The malware targets browser credentials, cookies, cryptocurrency wallets, seed phrases, and Telegram data, highlighting the growing abuse of trusted open-source ecosystems for credential theft.  

    Indicators of Compromise (IOC) List

    DOmain/Urls

    http://193.70.34.101:20099/vote

    https://upload.gofile.io/uploadfile

    https://gofile.io/d/

    https://api.ipify.org

    http://dresslee.com:20027/xf39jMJ9P1

    https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe

    release-assets.githubusercontent.com/github-production-release-asset/1334756299/1fccddb3-ab7e-408d-afbb-b139111b0b50

    dresslee.com

    IP Address

    193.70.34.101

    Hash

    1afff50ca4064310d3492c652e1c3168216dcb42063e0b26c223038db46b8731

    2edf1494951ea52eb86c606212668822081b3c589b821e8ec33cde59b65141a7

    67719fa6fcaa97936bf678565d6777db5c194e14efeba16864be8dac966e24bc

    6f088ade49456db2422c3edfbb9998f4a3e9cce7c4c00a7279fb45d672a82b7d

    a280b369c95b04530af11598f15a58328722af0325509fe1c55028c3fa873111

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://upload.gofile.io/uploadfile" or url like "https://upload.gofile.io/uploadfile" or siteurl like "https://upload.gofile.io/uploadfile" or domainname like "http://193.70.34.101:20099/vote" or url like "http://193.70.34.101:20099/vote" or siteurl like "http://193.70.34.101:20099/vote" or domainname like "https://gofile.io/d/" or url like "https://gofile.io/d/" or siteurl like "https://gofile.io/d/" or domainname like "https://api.ipify.org" or url like "https://api.ipify.org" or siteurl like "https://api.ipify.org" or domainname like "http://dresslee.com:20027/xf39jMJ9P1" or url like "http://dresslee.com:20027/xf39jMJ9P1" or siteurl like "http://dresslee.com:20027/xf39jMJ9P1" or domainname like "https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe" or url like "https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe" or siteurl like "https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe" or domainname like "dresslee.com" or url like "dresslee.com" or siteurl like "dresslee.com" or domainname like "release-assets.githubusercontent.com/github-production-release-asset/1334756299/1fccddb3-ab7e-408d-afbb-b139111b0b50" or url like "release-assets.githubusercontent.com/github-production-release-asset/1334756299/1fccddb3-ab7e-408d-afbb-b139111b0b50" or siteurl like "release-assets.githubusercontent.com/github-production-release-asset/1334756299/1fccddb3-ab7e-408d-afbb-b139111b0b50"

    Detection Query 2 :

    dstipaddress IN ("193.70.34.101") or srcipaddress IN ("193.70.34.101")

    Detection Query 3 :

    sha256hash IN ("6f088ade49456db2422c3edfbb9998f4a3e9cce7c4c00a7279fb45d672a82b7d","67719fa6fcaa97936bf678565d6777db5c194e14efeba16864be8dac966e24bc","1afff50ca4064310d3492c652e1c3168216dcb42063e0b26c223038db46b8731","a280b369c95b04530af11598f15a58328722af0325509fe1c55028c3fa873111","2edf1494951ea52eb86c606212668822081b3c589b821e8ec33cde59b65141a7")

    Reference: 

    https://opensourcemalware.com/blog/stubmaker-rubygems-windows-infostealer         


    Tags

    MalwareInfostealerPhishingSupply chain attackRust MalwareGitHubGolangCredential HarvestingcryptocurrencyTelegram

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags