<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Info-Stealer on CuraSec</title><link>https://curasec.metacog.co.kr/tags/info-stealer/</link><description>Recent content in Info-Stealer on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 11:36:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/info-stealer/index.xml" rel="self" type="application/rss+xml"/><item><title>16 Typosquatted RubyGems Packages Deploy StubMaker Info-Stealer</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-16-typosquatted-rubygems-packages-steal-browser-credentials/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-16-typosquatted-rubygems-packages-steal-browser-credentials/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active malicious packages in a public registry represent a live supply-chain threat. Audit all Gemfile.lock files and CI build logs for the named packages (ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn); rotate browser credentials and secrets from any Windows developer or runner machines where matches are found.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Sweep Windows developer workstations for StubMaker stealer artifacts and search CI/CD build logs for gem install activity referencing the named packages since August 15, 2026; focus on credential and crypto wallet exfiltration indicators on affected hosts.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm Ruby usage across engineering teams and verify that current dependency scanning controls would detect typosquatted packages before they reach production or developer machines; this campaign is a concrete prompt to close any gap in software supply chain policy this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Maps 30+ Domains to MacSync Stealer macOS Infra</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-microsoft-links-30-rotating-domains-to-macsync-stealer-infra/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-microsoft-links-30-rotating-domains-to-macsync-stealer-infra/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> MacSync Stealer targets macOS endpoints; the behavioral profile (payload retrieval → staging → exfiltration) is useful for validating EDR coverage on Mac fleets, but no patch or configuration change is indicated.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft published 30+ rotating domains tied to MacSync Stealer with multi-stage behavioral signatures; sweep DNS and proxy logs for these domains and hunt for correlated endpoint behaviors (payload fetch, local staging) on macOS hosts since the infrastructure became active.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A credible Microsoft-sourced macOS stealer campaign analysis worth noting for threat landscape awareness, but no systemic vendor breach, regulatory trigger, or board-level event is present here.&lt;/li>
&lt;/ul></description></item></channel></rss>