Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Cursor admits its new coding model was built on top of Moonshot AI’s Kimi

    March 22, 2026

    Delve accused of misleading customers with ‘fake compliance’

    March 21, 2026

    AI startups are eating the venture industry and the returns, so far, are good

    March 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Cursor admits its new coding model was built on top of Moonshot AI’s Kimi
    • Delve accused of misleading customers with ‘fake compliance’
    • AI startups are eating the venture industry and the returns, so far, are good
    • Bluesky announces $100M Series B after CEO transition
    • Consumer-focused privacy company Cloaked raises $375M as it expands to enterprise
    • Tools for founders to navigate and move past conflict
    • K2 to launch its first high-powered satellite for space compute
    • Anori, Alphabet’s new X spinout, is tackling one of the world’s most expensive bureaucratic nightmares
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Supply chain attack hits RubyGems to steal Telegram API data
    Security

    Supply chain attack hits RubyGems to steal Telegram API data

    TechurzBy TechurzJune 7, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Telegram app
    Share
    Facebook Twitter LinkedIn Pinterest Email


    An ongoing supply chain attack is targeting the RubyGems ecosystem to publish malicious packages intended to steal sensitive Telegram data.

    Published by a threat actor using multiple accounts under aliases Bùi nam, buidanhnam, and si_mobile, the malicious gems (ruby packages) pose as legitimate Fastlane plugins and exfiltrate data to an actor-controlled command and control (C2) server. Fastlane is a popular open-source tool, used extensively in CI/CD pipelines, to automate building, testing, and releasing mobile apps (iOS and Android).

    “Malicious actors take advantage of the trust inherent in open-source environments by embedding harmful code that can jeopardize systems, steal sensitive information, or, in this case, misdirect critical API traffic,” said Eric Schwake, director of cybersecurity strategy at Salt Security. “The identification of certain Ruby gems aimed at exfiltrating Telegram API tokens and messages highlights a significant and ongoing risk to the software supply chain.”

    API Attack Chain data Hits RubyGems steal Supply Telegram
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow to Check for an iPhone Carrier Settings Update
    Next Article Microcurrent Devices: Do They Work and Are They Worth It? We Asked Skin Experts
    Techurz
    • Website

    Related Posts

    Opinion

    Another deep tech chip startup becomes a unicorn: Frore hits $1.64B

    March 16, 2026
    Opinion

    Sales automation startup Rox AI hits $1.2B valuation, sources say

    March 12, 2026
    Opinion

    Quince hits $10B valuation with giant $500M round led by Iconiq

    March 11, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Cursor admits its new coding model was built on top of Moonshot AI’s Kimi

    March 22, 2026

    Delve accused of misleading customers with ‘fake compliance’

    March 21, 2026

    AI startups are eating the venture industry and the returns, so far, are good

    March 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.