gem · Malicious package advisory
Malwareutxo-set-utils
GHSA-6gvx-6r6p-9rgm
Malicious code in utxo-set-utils (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (7dbd653d2b6e9dead4140f0538bb92092348b726319930b322d6c6346dd7b668) ext/utxo-set-utils/extconf.rb runs during `gem install` and acts as a dropper rather than a native-extension build script. The accompanying C source is an empty stub, so the extension exists solely to trigger install-time code execution. extconf.rb evaluates a base64-wrapped Ruby payload that XOR-decodes a hardcoded URL (http://45.138.122.177:802/wgkit.tar.gz) using key 'usv\x9a', then curls the tarball to /tmp/.w1.tgz, extracts it, and runs bash on wg_install.sh from the archive. Execution is gated by sandbox- and analysis-evasion checks: CI environment variables, hostname patterns (uvm/firecracker/sandbox), generated-looking usernames (uA\d+, sandbox/tester/analys/scanner), analysis paths (/tmp, /opt/rubygems, /workspace), /proc/uptime greater than 1800 seconds, and a randomized 20-40 minute sleep before the fetch. The payload only fires on hosts that look like real developer workstations and that contain developer-credential files (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle), aligning the delivery with harvesting of RubyGems publisher tokens, SSH keys, and Git/npm credentials. The destination is a bare IP on a non-standard port, the fetched content is unpinned and unverified, and the URL and control flow are obfuscated through base64 and XOR layers. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/utxo-set-utils/MAL-2026-17613.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/utxo-set-utils/MAL-2026-17613.json - https://rubygems.org/gems/utxo-set-utils/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/utxo-set-utils/MAL-2026-17613.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/utxo-set-utils/MAL-2026-17613.json - https://github.com/advisories/GHSA-6gvx-6r6p-9rgm
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.