VYPR

gem · Malicious package advisory

Malware

coinmarket-utils

GHSA-f63h-97qr-7h9q

Malicious code in coinmarket-utils (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (7ace1863ec858e5931ba2848276c14fb050fff204b2fbea82e2f64ae3f9a0ffc)
The gem's native extension build script ext/coinmarket-utils/extconf.rb contains a base64-encoded Ruby payload that is decoded and eval'd inside a double-forked, setsid, FD-detached child process at `gem install` time. The payload XOR-decodes a hardcoded destination URL (http://45.138.12.177:8092/wgkit.tar.gz) from a hex blob, shells out to curl to download the tarball to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes wg_install.sh via bash. Execution is gated by sandbox-evasion checks that skip CI environments, ephemeral VMs, analysis paths, generated usernames, and hosts with uptime under 30 minutes, and that require developer artifacts (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) to be present on disk — firing only on real developer workstations. The accompanying C source ext/coinmarket-utils/coinmarket-utils.c is an empty stub (`Init_CoinmarketUtils(void) {}`) with no real native code to compile, and the lib entry only returns a hardcoded wordlist; the native extension exists solely to cause extconf.rb to run on install. Combined fingerprints: install-time fetch-and-execute from a hardcoded bare-IP C2 on a non-standard port, multi-layer obfuscation (base64 + XOR + eval), process detachment to orphan the dropper from the install process, developer-workstation targeting with explicit sandbox evasion, and a cover-story extension with no legitimate build purpose.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/coinmarket-utils/MAL-2026-17590.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/coinmarket-utils/MAL-2026-17590.json
- https://rubygems.org/gems/coinmarket-utils/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/coinmarket-utils/MAL-2026-17590.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/coinmarket-utils/MAL-2026-17590.json
- https://github.com/advisories/GHSA-f63h-97qr-7h9q

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.