gem · Malicious package advisory
Malwareetherdum.rb
GHSA-f6c2-r38w-6v9x
Malicious code in etherdum.rb (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (a27b2952de0064d1745d45f18fc1ab974e48cfe185b8f41e90447265be1a880f) The gem declares ext/etherdum.rb/extconf.rb as a native extension, but the accompanying C source is an empty Init stub and the Ruby library is a trivial word list with no cryptography. extconf.rb, which RubyGems runs automatically on `gem install`, base64-decodes and evals a Ruby payload that XOR-decodes a hardcoded URL (http://45.138.217.89:2/wgkit.tar.gz, overridable via WG_KIT_URL), downloads a tarball to /tmp/.w1.tgz, extracts it, and executes wg_install.sh over plaintext HTTP from a bare IP. Execution is wrapped in a double-forked, detached child with stdio redirected to /dev/null and a 20-40 minute sleep before firing. Anti-analysis gating skips CI environments, ephemeral/sandbox hostnames (uvm, firecracker, sandbox, vagrant, fc-vm), generated-looking usernames (uA\d+, sandbox/tester/analys/scanner), analysis paths (/opt/rubygems, /tmp, /workspace), machines with uptime under 1800 seconds, and systems lacking developer artifacts, requiring the presence of ~/.ssh, ~/.gem/credentials, ~/.bundle,.gitconfig, or.npmrc before executing. The package name typosquats 'ethereum' and the native-extension declaration exists solely to trigger extconf.rb execution. Installing this gem on a developer workstation yields remote code execution via an unpinned, attacker-controlled shell script. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/etherdum.rb/MAL-2026-17599.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/etherdum.rb/MAL-2026-17599.json - https://rubygems.org/gems/etherdum.rb/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/etherdum.rb/MAL-2026-17599.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/etherdum.rb/MAL-2026-17599.json - https://github.com/advisories/GHSA-f6c2-r38w-6v9x
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.