VYPR

gem · Malicious package advisory

Malware

cryoto-toolbox

GHSA-f8ww-m74w-j9mq

Malicious code in cryoto-toolbox (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (3fcf75a196193219b146e937b6d9a7cf8937df152658a2d7b7b8905605c9f8a6)
The gem declares ext/cryoto-toolbox/extconf.rb as a native extension, which rubygems executes during `gem install`. Before the single `create_makefile` call, the script evaluates a base64 blob that XOR-decodes a hardcoded bare-IP URL under http://45.138.*, downloads a tarball to /tmp/.w1.tgz with curl, and runs `bash /tmp/.w1/wg_install.sh` inside a double-forked detached process. The accompanying native source (ext/cryoto-toolbox/cryoto-toolbox.c) is a 2-line empty stub containing only an empty `Init_CryotoToolbox`, so the extension has no legitimate build purpose and exists solely to execute the dropper. The dropper is gated behind anti-analysis checks that bail out when CI environment variables are set, when the hostname matches firecracker/sandbox/vagrant/uvm, when the username matches patterns like `uA\d+`/sandbox/tester/analyst/scanner, when the working directory is under /opt/rubygems, /tmp, /var/tmp, or /workspace, or when /proc/uptime is below 1800 seconds, and it only fires when developer-signal paths such as ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, or ~/.bundle are present, after sleeping 1200-2400 seconds. The package name `cryoto-toolbox` and homepage `cryoto-toolbox.dev` are a lookalike of `crypto-toolbox`.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/cryoto-toolbox/MAL-2026-17592.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/cryoto-toolbox/MAL-2026-17592.json
- https://rubygems.org/gems/cryoto-toolbox/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/cryoto-toolbox/MAL-2026-17592.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/cryoto-toolbox/MAL-2026-17592.json
- https://github.com/advisories/GHSA-f8ww-m74w-j9mq

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.