gem · Malicious package advisory
Malwareeth-address-utils
GHSA-cg29-22qj-86m4
Malicious code in eth-address-utils (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (8ed9d372d4fc694697be41c22e7c4d02d873e53e16bde2336069787b7b961ce2) The gem advertises itself as an Ethereum address utility library but its extconf.rb (auto-executed by `gem install`) carries a base64-encoded payload that is decoded and passed to `eval` inside a double-forked, detached background process. The decoded payload sleeps 20-40 minutes and then opens a TCPSocket to the hardcoded remote host 45.138.12.177 on port 8090, bridging the socket to `IO.popen(['/bin/sh'],'r+')` — a reverse shell giving the operator of that IP full remote code execution on the installer's host under the installing user's privileges. The extension declares a native component named `req_throttle_mini` but ships no corresponding C sources; `create_makefile` is appended only as camouflage. Payload execution is gated by anti-analysis checks that skip CI environments, ephemeral/sandbox hostnames (uvm/firecracker/sandbox/vagrant), synthetic analyst usernames (sandbox/tester/analys/scanner), build paths under /tmp, /opt/rubygems, /workspace, systems with uptime under 1800 seconds, and hosts lacking developer-identity artifacts such as ~/.ssh, ~/.gitconfig, ~/.gem/credentials, or ~/.bundle — so only real developer workstations are compromised. The library name, the fake native-extension stub, and the sandbox evasion together confirm this is a disguised remote-access implant, not a build helper. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json - https://rubygems.org/gems/eth-address-utils/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json - https://github.com/advisories/GHSA-cg29-22qj-86m4
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.