VYPR

gem · Malicious package advisory

Malware

kecack

GHSA-fj4h-hgwh-qmc6

Malicious code in kecack (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (f17f86c78cebe16698b84a8ab5a9b87865c63a890588c23fbe1d2638c4501647)
The gem's native extension build script (ext/.../extconf.rb) executes during `gem install` and contains a dropper rather than a real native build. Before `create_makefile`, it enumerates environment indicators to suppress itself inside analysis infrastructure: CI environment variables, hostname patterns matching uvm/firecracker/sandbox/vagrant, usernames matching sandbox/tester/analys/scanner, build paths under /opt/rubygems or /tmp, and a /proc/uptime check requiring the host to have been running for more than ~30 minutes. It additionally requires developer-credential artifacts to be present on disk (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc) before proceeding. When the gating passes, it double-forks, sleeps 20-40 minutes, then base64-decodes and eval's a Ruby payload that reconstructs a URL via XOR of a byte array, downloads http://45.138.122.177:8092/wgkit.tar.gz to /tmp/.w1.tgz, extracts to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh. The shipped native source is a trivial empty Init_Kecack stub with no real C functionality — the extension exists only to carry the dropper. The target host 45.138.122.177 is a bare IP unrelated to any legitimate publisher, the fetched content is unpinned and unverified, and the URL is obfuscated with XOR+base64.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/kecack/MAL-2026-17603.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/kecack/MAL-2026-17603.json
- https://rubygems.org/gems/kecack/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/kecack/MAL-2026-17603.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/kecack/MAL-2026-17603.json
- https://github.com/advisories/GHSA-fj4h-hgwh-qmc6

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.