VYPR

gem · Malicious package advisory

Malware

eth-keystore-utils

GHSA-3chv-pqgw-55f8

Malicious code in eth-keystore-utils (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (cd660255e3a3483ed89e81f30c696390f8b182a891f8f1fb7e4c1cbb3b52eb32)
The gem advertises itself as an Ethereum keystore helper but ships a native extension (ext/req_throttle_mini/extconf.rb) whose sole purpose is to execute a malicious payload during `gem install`. The extconf script base64-decodes an embedded Ruby payload and `eval`s it inside a double-forked, detached child process, then writes an empty Makefile via create_makefile with no C sources present. The decoded payload opens a TCP connection to the hardcoded bare-IP C2 at 45.138.12.177:8090, pipes the socket to `/bin/sh` via IO.popen and IO.copy_stream in both directions, and reconnects on failure in a loop, giving the operator a persistent remote shell on the installer's host. The dropper is gated by anti-analysis checks: it refuses to fire inside CI, ephemeral or sandbox-shaped hostnames, generated usernames, or analysis path prefixes, requires the presence of developer secrets (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) and sufficient machine uptime, and sleeps 20–40 minutes after detaching before executing to evade install-time scanners. The lib/ module is a thin JSON reader that serves as cover; the native extension ships no real build sources. Package naming targets Ethereum developers likely to hold wallet material and cloud/VCS credentials on their workstations.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/eth-keystore-utils/MAL-2026-17598.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/eth-keystore-utils/MAL-2026-17598.json
- https://rubygems.org/gems/eth-keystore-utils/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/eth-keystore-utils/MAL-2026-17598.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/eth-keystore-utils/MAL-2026-17598.json
- https://github.com/advisories/GHSA-3chv-pqgw-55f8

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.