<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rubygems on CuraSec</title><link>https://curasec.metacog.co.kr/tags/rubygems/</link><description>Recent content in Rubygems on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 11:36:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/rubygems/index.xml" rel="self" type="application/rss+xml"/><item><title>16 Typosquatted RubyGems Packages Deploy StubMaker Info-Stealer</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-16-typosquatted-rubygems-packages-steal-browser-credentials/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-16-typosquatted-rubygems-packages-steal-browser-credentials/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active malicious packages in a public registry represent a live supply-chain threat. Audit all Gemfile.lock files and CI build logs for the named packages (ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn); rotate browser credentials and secrets from any Windows developer or runner machines where matches are found.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Sweep Windows developer workstations for StubMaker stealer artifacts and search CI/CD build logs for gem install activity referencing the named packages since August 15, 2026; focus on credential and crypto wallet exfiltration indicators on affected hosts.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm Ruby usage across engineering teams and verify that current dependency scanning controls would detect typosquatted packages before they reach production or developer machines; this campaign is a concrete prompt to close any gap in software supply chain policy this quarter.&lt;/li>
&lt;/ul></description></item><item><title>SleeperGem: Three Malicious RubyGems Target Developer Machines</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-sleepergem-uses-three-malicious-rubygems-packages-to-target/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-sleepergem-uses-three-malicious-rubygems-packages-to-target/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If you have Ruby projects, audit all dependency trees for git_credential_manager versions 2.8.0–2.8.3 and Dendreo versions 1.1.3–1.1.4; remove immediately and treat any developer machine that installed them since July 18 as potentially compromised.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Hunt for installations of these specific gem versions in developer endpoint EDR telemetry and CI/CD build logs since July 18, 2026; any confirmed install warrants an assume-breach sweep of that machine for secondary payload execution.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization has Ruby developers, direct the engineering team to audit for these packages and assess developer workstation exposure this week — credential-stealing supply chain hits on dev machines can pivot to production secrets.&lt;/li>
&lt;/ul></description></item></channel></rss>