16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have identified a major typosquatting campaign targeting RubyGems users with a Windows-based information stealer, linked to the OpenSourceMalware team, affecting 16 packages published between August 20, 2026, and September 1, 2026.

Bottom line: 16 RubyGems packages were compromised in a typosquatting campaign linked to OpenSourceMalware, exposing users to browser credentials and crypto wallets.

What's happening: Cybersecurity researchers OpenSourceMalware detected the campaign on August 15, 2026, targeting users of popular gems like unicorn-ruby and sass-assetutils.

What to do: Security teams should monitor RubyGems repositories for suspicious activity and update affected packages to prevent further exploitation.

Source: The Hacker News