VYPR

gem · Malicious package advisory

Malware

eth-address-utils

GHSA-cg29-22qj-86m4

Malicious code in eth-address-utils (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (8ed9d372d4fc694697be41c22e7c4d02d873e53e16bde2336069787b7b961ce2)
The gem advertises itself as an Ethereum address utility library but its extconf.rb (auto-executed by `gem install`) carries a base64-encoded payload that is decoded and passed to `eval` inside a double-forked, detached background process. The decoded payload sleeps 20-40 minutes and then opens a TCPSocket to the hardcoded remote host 45.138.12.177 on port 8090, bridging the socket to `IO.popen(['/bin/sh'],'r+')` — a reverse shell giving the operator of that IP full remote code execution on the installer's host under the installing user's privileges. The extension declares a native component named `req_throttle_mini` but ships no corresponding C sources; `create_makefile` is appended only as camouflage. Payload execution is gated by anti-analysis checks that skip CI environments, ephemeral/sandbox hostnames (uvm/firecracker/sandbox/vagrant), synthetic analyst usernames (sandbox/tester/analys/scanner), build paths under /tmp, /opt/rubygems, /workspace, systems with uptime under 1800 seconds, and hosts lacking developer-identity artifacts such as ~/.ssh, ~/.gitconfig, ~/.gem/credentials, or ~/.bundle — so only real developer workstations are compromised. The library name, the fake native-extension stub, and the sandbox evasion together confirm this is a disguised remote-access implant, not a build helper.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json
- https://rubygems.org/gems/eth-address-utils/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json
- https://github.com/advisories/GHSA-cg29-22qj-86m4

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.