Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious Ruby Gems Exfiltrate Telegram Tokens and Messages ...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
1,025
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

In response to Vietnam's nationwide ban on Telegram, a threat actor exploited the situation by releasing two malicious Ruby gems impersonating legitimate Fastlane plugins, designed to steal Telegram bot tokens, messages, and files. These gems, named with slight variations like `fastlane-plugin-telegram-proxy` and `fastlane-plugin-proxy_teleram`, redirected data through a command and control server controlled by the attacker, under the guise of providing a proxy service. The campaign was strategically timed to target developers seeking Telegram workarounds post-ban, leveraging the trust in package ecosystems to infiltrate CI/CD workflows globally, despite the initial targeting of Vietnam-based developers. The malicious code did not limit its execution geographically, posing a broader threat to any environment where these gems were installed, leading to credential theft and data exfiltration. Organizations are advised to remove these gems, lock trusted dependency versions, and rotate compromised Telegram tokens to mitigate the impact of this supply chain attack.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.