Date: 08/18/2026
Severity: High
Summary
The StubMaker campaign is a RubyGems supply chain attack that distributed typosquatted Ruby packages containing malicious extconf.rb installer hooks to compromise Windows developer systems. During installation, the packages fingerprint the host, download a Rust-based loader from GitHub Releases, and decrypt an embedded Go infostealer entirely in memory for fileless execution. The malware targets browser credentials, cookies, cryptocurrency wallets, seed phrases, and Telegram data, highlighting the growing abuse of trusted open-source ecosystems for credential theft.
Indicators of Compromise (IOC) List
DOmain/Urls | http://193.70.34.101:20099/vote https://upload.gofile.io/uploadfile https://gofile.io/d/ https://api.ipify.org http://dresslee.com:20027/xf39jMJ9P1 https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe release-assets.githubusercontent.com/github-production-release-asset/1334756299/1fccddb3-ab7e-408d-afbb-b139111b0b50 dresslee.com |
IP Address | 193.70.34.101 |
Hash | 1afff50ca4064310d3492c652e1c3168216dcb42063e0b26c223038db46b8731
2edf1494951ea52eb86c606212668822081b3c589b821e8ec33cde59b65141a7
67719fa6fcaa97936bf678565d6777db5c194e14efeba16864be8dac966e24bc
6f088ade49456db2422c3edfbb9998f4a3e9cce7c4c00a7279fb45d672a82b7d
a280b369c95b04530af11598f15a58328722af0325509fe1c55028c3fa873111
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "https://upload.gofile.io/uploadfile" or url like "https://upload.gofile.io/uploadfile" or siteurl like "https://upload.gofile.io/uploadfile" or domainname like "http://193.70.34.101:20099/vote" or url like "http://193.70.34.101:20099/vote" or siteurl like "http://193.70.34.101:20099/vote" or domainname like "https://gofile.io/d/" or url like "https://gofile.io/d/" or siteurl like "https://gofile.io/d/" or domainname like "https://api.ipify.org" or url like "https://api.ipify.org" or siteurl like "https://api.ipify.org" or domainname like "http://dresslee.com:20027/xf39jMJ9P1" or url like "http://dresslee.com:20027/xf39jMJ9P1" or siteurl like "http://dresslee.com:20027/xf39jMJ9P1" or domainname like "https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe" or url like "https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe" or siteurl like "https://github.com/bebraz1/qPzM50V1AKG0rVlH/releases/download/null/main.exe" or domainname like "dresslee.com" or url like "dresslee.com" or siteurl like "dresslee.com" or domainname like "release-assets.githubusercontent.com/github-production-release-asset/1334756299/1fccddb3-ab7e-408d-afbb-b139111b0b50" or url like "release-assets.githubusercontent.com/github-production-release-asset/1334756299/1fccddb3-ab7e-408d-afbb-b139111b0b50" or siteurl like "release-assets.githubusercontent.com/github-production-release-asset/1334756299/1fccddb3-ab7e-408d-afbb-b139111b0b50" |
Detection Query 2 : | dstipaddress IN ("193.70.34.101") or srcipaddress IN ("193.70.34.101") |
Detection Query 3 : | sha256hash IN ("6f088ade49456db2422c3edfbb9998f4a3e9cce7c4c00a7279fb45d672a82b7d","67719fa6fcaa97936bf678565d6777db5c194e14efeba16864be8dac966e24bc","1afff50ca4064310d3492c652e1c3168216dcb42063e0b26c223038db46b8731","a280b369c95b04530af11598f15a58328722af0325509fe1c55028c3fa873111","2edf1494951ea52eb86c606212668822081b3c589b821e8ec33cde59b65141a7")
|
Reference:
https://opensourcemalware.com/blog/stubmaker-rubygems-windows-infostealer