gem · Malicious package advisory
Malwarekeccka
GHSA-9c95-4459-6pcw
Malicious code in keccka (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (e4f005ef5a4a20f9aadcdd2c6e78e6d68bb52765b2f5fac2abee6abd7dd261c5) The gem's native extension is a cover: ext/keccka/keccka.c is an empty stub and extconf.rb — auto-executed by `gem install` — contains a base64-wrapped Ruby payload decoded and passed to eval. The payload XOR-decodes a hardcoded C2 URL (http://45.138.12.177:8092/wgkit.tar.gz), curls the tarball over plain HTTP to a bare IP, and runs `bash /tmp/.w1/wg_install.sh` from the extracted content. Execution is gated by anti-analysis checks: it skips when CI environment variables are set (CI, GITHUB_ACTIONS, TRAVIS, JENKINS_URL, GITLAB_CI, CODESPACES), when the hostname matches ephemeral/sandbox patterns (firecracker, sandbox, vagrant), when the username looks generated (sandbox, tester, analys, scanner, uA\d+), when the working directory is an analysis path (/tmp, /opt/rubygems, /workspace), or when system uptime is under 1800 seconds, and it requires developer-looking signals on disk (~/.ssh, ~/.gitconfig, ~/.gem/credentials). On a matching host it double-forks a detached child that sleeps 20-40 minutes before fetching and executing. The destination is a plaintext, unauthenticated bare-IP host unrelated to any legitimate publisher; the fetched shell script is unpinned, unverified, and attacker-controlled. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/keccka/MAL-2026-17604.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/keccka/MAL-2026-17604.json - https://rubygems.org/gems/keccka/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/keccka/MAL-2026-17604.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/keccka/MAL-2026-17604.json - https://github.com/advisories/GHSA-9c95-4459-6pcw
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.