VDB

GCVE-110-OSM-2026-10515

GCVE-110-OSM-2026-10515
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 15, 2026
This package was published by someone claiming to be Taylor Moore to the Rubygems registry. This package has no description or README, but appears to be a very crude typosquat attack. Ie., brumdler instead of bundler? Regardless, this package delivers a fairly sophisticated and novel Windows based malware. This is a multistage kill chain with IPs, and multiple c2 domains. Like many of the software supply chain malware attacks we are seeing, this one is both an infostealer and cryptostealer. Additionally, this malware appears to target the Brew ecosytem via the lib/install_core/runner.rb file. OBFUSCATION - Decoded Base64 Content in rubygems/brundlef@1.0.37871/lib/install_core/runner.rb (x4) - recovered 2 urls, 1 ips from decoded/deobfuscated content ADDITIONAL FINDINGS - Homebrew Ruby Remote Require in rubygems/brundlef@1.0.37871/lib/install_core/runner.rb: "require 'open-uri'" - Homebrew Ruby Backtick/Kernel Execution in rubygems/brundlef@1.0.37871/lib/install_core/runner.rb: "Open3.popen2e" - Homebrew Ruby Process Spawning in rubygems/brundlef@1.0.37871/lib/install_core/runner.rb: "Process.spawn" PAYLOAD FILES rubygems/brundlef@1.0.37871/lib/install_core/runner.rb

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownbrundlefall (affected)

References

vendor

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›