CuraSec

tag: Info-Stealer · 2 items

2026-08-19 · The Hacker News · source ↗ #macos#info-stealer#threat-intel
  • Engineer — Learn: MacSync Stealer targets macOS endpoints; the behavioral profile (payload retrieval → staging → exfiltration) is useful for validating EDR coverage on Mac fleets, but no patch or configuration change is indicated.
  • SOC/IR — Act: Microsoft published 30+ rotating domains tied to MacSync Stealer with multi-stage behavioral signatures; sweep DNS and proxy logs for these domains and hunt for correlated endpoint behaviors (payload fetch, local staging) on macOS hosts since the infrastructure became active.
  • Leader — Learn: A credible Microsoft-sourced macOS stealer campaign analysis worth noting for threat landscape awareness, but no systemic vendor breach, regulatory trigger, or board-level event is present here.
2026-08-19 · The Hacker News · source ↗ #supply-chain#rubygems#info-stealer
  • Engineer — Act: Active malicious packages in a public registry represent a live supply-chain threat. Audit all Gemfile.lock files and CI build logs for the named packages (ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn); rotate browser credentials and secrets from any Windows developer or runner machines where matches are found.
  • SOC/IR — Act: Sweep Windows developer workstations for StubMaker stealer artifacts and search CI/CD build logs for gem install activity referencing the named packages since August 15, 2026; focus on credential and crypto wallet exfiltration indicators on affected hosts.
  • Leader — Plan: Confirm Ruby usage across engineering teams and verify that current dependency scanning controls would detect typosquatted packages before they reach production or developer machines; this campaign is a concrete prompt to close any gap in software supply chain policy this quarter.