VDB
GCVE-110-OSM-2026-10515
GCVE-110-OSM-2026-10515
Advisory PublishedCVSS 8.8/10
This package was published by someone claiming to be Taylor Moore to the Rubygems registry. This package has no description or README, but appears to be a very crude typosquat attack. Ie., brumdler instead of bundler?
Regardless, this package delivers a fairly sophisticated and novel Windows based malware. This is a multistage kill chain with IPs, and multiple c2 domains.
Like many of the software supply chain malware attacks we are seeing, this one is both an infostealer and cryptostealer.
Additionally, this malware appears to target the Brew ecosytem via the lib/install_core/runner.rb file.
OBFUSCATION
- Decoded Base64 Content in rubygems/brundlef@1.0.37871/lib/install_core/runner.rb (x4)
- recovered 2 urls, 1 ips from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Homebrew Ruby Remote Require in rubygems/brundlef@1.0.37871/lib/install_core/runner.rb: "require 'open-uri'"
- Homebrew Ruby Backtick/Kernel Execution in rubygems/brundlef@1.0.37871/lib/install_core/runner.rb: "Open3.popen2e"
- Homebrew Ruby Process Spawning in rubygems/brundlef@1.0.37871/lib/install_core/runner.rb: "Process.spawn"
PAYLOAD FILES
rubygems/brundlef@1.0.37871/lib/install_core/runner.rb
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | brundlef | all (affected) | — |
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.