VYPR

gem · Malicious package advisory

Malware

crypto-key-utils

GHSA-9vq6-8jf2-mh9q

Malicious code in crypto-key-utils (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (559eb6e590366fcb8968de4964d8eb9d61ad6149a1ce1d4696ff4f64bff1a214)
The gem declares a native extension whose extconf.rb is the attack vehicle: the C source (ext/crypto-key-utils/crypto-key-utils.c) is a two-line empty Init stub, and create_makefile is only reached after a block of install-time logic. On `gem install`, extconf.rb runs sandbox/analysis evasion gates — skipping execution under CI, under analysis path prefixes (/tmp, /opt/rubygems, /workspace, /private/var/tmp), under generated usernames (uA\d+, sandbox/tester/analys/scanner), on ephemeral hostnames (uvm, firecracker, sandbox, vagrant), and when /proc/uptime is below 1800 seconds — and requires developer-host signals (presence of ~/.ssh, ~/.gem/credentials, ~/.npmrc, ~/.bundle). When the gates pass, it base64-decodes an embedded Ruby payload and double-forks it. The payload XOR-decodes a hardcoded URL (hex blob XORed with key "usv\x9a") resolving to http://45.138.127.77:8092/wgkit.tar.gz, sleeps a randomized 20–40 minutes, curls the tarball to /tmp/.w1.tgz over plain HTTP with no verification, extracts it, and executes bash /tmp/.w1/wg_install.sh. The lib/crypto-key-utils.rb entry is an unrelated BIP-39-style word list and does not implement the DER/PEM functionality the gem advertises.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypto-key-utils/MAL-2026-17594.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypto-key-utils/MAL-2026-17594.json
- https://rubygems.org/gems/crypto-key-utils/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/crypto-key-utils/MAL-2026-17594.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/crypto-key-utils/MAL-2026-17594.json
- https://github.com/advisories/GHSA-9vq6-8jf2-mh9q

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.