gem · Malicious package advisory
Malwareblockchain-sync-utils
GHSA-fp5m-6565-9wg5
Malicious code in blockchain-sync-utils (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (78a8b7d5a56c33e17464f8129001559f02bd245cd299cb8cb07ccc334eb5af65) The gem's native-extension build script (ext/.../extconf.rb) is a dropper rather than a real build step. The accompanying C source is a no-op stub, so the extension exists only to run install-time code. The script decodes a base64-wrapped Ruby payload and eval()s it inside a detached double-fork (Process.setsid), after gating on anti-analysis checks (CI environment variables, hostname regex, /proc/uptime greater than 1800 seconds, jittered sleep) and on the presence of developer-credential artifacts on the host (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) so the payload only fires on real developer workstations. The payload's destination URL is stored as a hex blob XORed with a 4-byte key and resolves to http://45.138.122.177:8092/wgkit.tar.gz; the decoded command curls that tarball to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh. Installing the gem runs attacker-controlled shell code on the installer's machine from a bare-IP endpoint over plain HTTP, with no pinning or integrity check and with explicit sandbox evasion. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/blockchain-sync-utils/MAL-2026-17588.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/blockchain-sync-utils/MAL-2026-17588.json - https://rubygems.org/gems/blockchain-sync-utils/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/blockchain-sync-utils/MAL-2026-17588.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/blockchain-sync-utils/MAL-2026-17588.json - https://github.com/advisories/GHSA-fp5m-6565-9wg5
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.