Malicious RubyGems Packages Impersonate Popular Libraries to Steal Windows Credentials
Researchers flagged seven typosquatted gems on August 15, 2026, part of a wider campaign delivering a Windows information stealer.

Key points
- OpenSourceMalware disclosed a typosquatting campaign against RubyGems users on August 15, 2026.
- The researchers named the activity StubMaker and linked it to a Windows information stealer.
- Seven look-alike package names have been published: ubnuler, ubnlder, ri18nr, reaker, rakier, orakw and joxn.
- Malicious gems mimic common Ruby library names, betting on developers mistyping a package name.
- Developers who installed any of the listed packages on Windows should treat that machine as compromised.
A fresh wave of fake software packages is targeting Ruby developers, and the goal is theft.
On August 15, 2026, the research group OpenSourceMalware said it had found a typosquatting campaign on RubyGems, the main repository Ruby programmers use to download open-source libraries. Typosquatting means publishing packages with names nearly identical to popular ones, hoping a developer mistypes a letter and installs the malicious version instead. The activity was first reported by The Hacker News.
OpenSourceMalware is tracking the campaign as StubMaker. It delivers an information stealer, malicious software designed to pull saved passwords, browser data and other secrets from a victim's machine. The payload targets Windows. We covered a related threat on 20 July in SleeperGem, when booby-trapped Ruby packages sat quietly on the registry waiting to fetch further attacker code.
Which packages are involved?
Seven gem names have been identified publicly. Each is a near-miss of a legitimate Ruby library.
| Malicious gem | Likely target |
|---|---|
| ubnuler | common utility name |
| ubnlder | common utility name |
| ri18nr | i18n (internationalisation) |
| reaker | rake (Ruby build tool) |
| rakier | rake |
| orakw | rake |
| joxn | json |
The pattern's consistent: drop a letter, swap a letter, add a letter. A tired developer running gem install is exactly who this preys on.
What does the malware actually do?
It steals data from Windows machines. OpenSourceMalware classes StubMaker as an information stealer, a category of malware that typically grabs saved browser passwords, session cookies and cryptocurrency wallet files. The campaign name refers to the stub, a small loader program the attackers use to launch the stealer once a developer runs the poisoned gem.
Ruby code often runs with the same permissions as the developer who installed it. If that developer has access to production keys or cloud credentials, the stealer can reach those too.
Should developers be worried?
Yes, if they work on Windows and install gems by hand. One mistyped command can hand over an entire workstation's secrets.
Anyone who installed one of the seven packages above should assume the machine is dirty. Rotate any passwords stored in the browser, revoke API tokens and cloud credentials that touched the box, and rebuild rather than trying to clean it.
Teams should also check their build servers. Continuous integration systems, the automated machines that compile and test code, often install gems from a lockfile. A single bad entry there spreads infection to every build.
Common questions
How do I tell if a RubyGems package is legitimate?
Check the exact spelling against the project's official site or GitHub repository before installing. A package a week old with a name close to a famous library is a red flag, especially if its download count and maintainer history are thin.
Does this affect Mac or Linux developers?
The stealer payload described by OpenSourceMalware targets Windows. Installing the malicious gem on macOS or Linux is still not safe, because the package itself is hostile, but the specific credential theft described here runs on Windows only.



