gem · Malicious package advisory
Malwareweb3-eth-utils
GHSA-847r-2824-c2jx
Malicious code in web3-eth-utils (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (248aba9be7a8bfbd125b43640f1c52007358e34078b3bfec5430933c996b8666) The gem declares a native extension at ext/req_throttle_mini/extconf.rb but ships no C/C++/Rust sources, so the extension entry exists solely to force extconf.rb to run during `gem install`. Before calling mkmf/create_makefile, extconf.rb executes sandbox-evasion checks (CI env vars, generated usernames, hostname patterns, /tmp working directories, uptime under 30 minutes, absence of ~/.ssh, ~/.gitconfig, and ~/.gem/credentials) and only proceeds on hosts that look like real developer workstations. It then base64-decodes an opaque Ruby payload and, inside a double-forked detached child that sleeps for a randomized 20-40 minute delay, passes the decoded string to eval(). The decoded payload opens a TCP socket to 45.138.12.177:8089, spawns /bin/sh, and bridges the socket to the shell in a reconnect loop, yielding a persistent reverse shell under the installing user. The package name mimics the web3/eth ecosystem and lib/web3_eth_utils.rb is a trivial stub, consistent with a typosquat lure whose only functional effect is the install-time hook. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/web3-eth-utils/MAL-2026-17616.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/web3-eth-utils/MAL-2026-17616.json - https://rubygems.org/gems/web3-eth-utils/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/web3-eth-utils/MAL-2026-17616.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/web3-eth-utils/MAL-2026-17616.json - https://github.com/advisories/GHSA-847r-2824-c2jx
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.