Cybercriminals Target RubyGems, Salesforce/ServiceNow, and Crypto Wallets—Are Supply Chains Next?
Cybersecurity researchers have flagged a new typosquatting campaign aimed at RubyGems users, using Windows-based information stealer packages published under lookalike names. OpenSourceMalware reported the activity on August 15, 2026 and is tracking it under the moniker StubMaker, indicating a deliberate attempt to harvest browser credentials and crypto wallet access. In parallel, research from Reco says a single attacker infrastructure has been scraping records from both Salesforce and ServiceNow customer portals since 2025, spanning multiple industries and earning the campaign name City Forum. Separately, SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed personal data and purchase details for roughly 39,798 customers, with affected users notified by email on August 8, 2026. Taken together, the cluster points to a coordinated pattern: credential theft and data exfiltration via software supply chains and enterprise SaaS ecosystems. RubyGems typosquatting targets developer workflows, while Salesforce/ServiceNow scraping targets business processes and customer identity data, creating a cross-layer threat that can be monetized through account takeover and fraud. The crypto-wallet angle matters geopolitically and economically because it accelerates distrust in digital custody and can amplify regulatory scrutiny of exchanges, wallet providers, and payment rails. The likely beneficiaries are financially motivated threat actors who can chain stolen credentials into downstream access, while the losers include enterprises with weak identity controls, smaller open-source maintainers, and consumers whose data is exposed through third-party plugins. Market implications are most visible in cybersecurity and compliance-sensitive sectors rather than in traditional commodities. Enterprise SaaS operators and their customers face rising costs for incident response, monitoring, and identity hardening, which can pressure near-term IT budgets and increase demand for security tooling. In the crypto ecosystem, SafePal’s customer-data exposure can weigh on sentiment around hardware wallets and may increase churn risk, especially if customers perceive operational negligence or insufficient authorization controls. While the articles do not provide direct price figures, the direction is risk-off for security posture: higher implied volatility for security vendors, identity platforms, and incident-response services, and potential short-term negative sentiment for wallet providers and adjacent fintech brands. Next, investors and risk teams should watch for indicators of follow-on exploitation, including additional typosquatted RubyGems packages, new StubMaker variants, and evidence of credential reuse against enterprise accounts. For City Forum, key triggers are whether the scraping expands to additional SaaS tenants, whether Reco identifies persistence mechanisms, and whether affected organizations report unauthorized data access beyond portal records. For SafePal, the critical timeline is whether the authorization flaw is fully patched across all order-tracking integrations and whether any secondary exposure (e.g., password resets or account takeovers) is detected. Escalation risk rises if stolen credentials are observed being used in real-world logins or if regulators begin inquiries into supply-chain and plugin authorization practices; de-escalation would be signaled by rapid patch verification, clean forensic reports, and no evidence of broader compromise beyond the stated customer sets.
Geopolitical Implications
- 01
Cross-sector credential theft and SaaS scraping can undermine trust in digital commerce and identity systems, increasing pressure for tighter cross-border cyber regulation and enforcement.
- 02
Crypto wallet data exposure can accelerate scrutiny of custody providers and payment-adjacent platforms, potentially affecting compliance standards and operational requirements.
- 03
Persistent targeting of widely used enterprise platforms (Salesforce/ServiceNow) raises the likelihood of broader multinational incident coordination and information-sharing demands.
Key Signals
- —New StubMaker package names and download spikes on RubyGems that match typosquatting patterns.
- —For City Forum: reports of unauthorized access beyond scraped portal records, tenant expansion, or persistence mechanisms.
- —For SafePal: confirmation that the plug-in authorization fix is deployed everywhere and that no secondary account-takeover activity is detected.
- —Threat-actor indicators showing credential reuse across SaaS and crypto login flows.
Topics & Keywords
Related Intelligence
Full Access
Unlock Full Intelligence Access
Real-time alerts, detailed threat assessments, entity networks, market correlations, AI briefings, and interactive maps.