VYPR

gem · Malicious package advisory

Malware

ethereum-tx-helper

GHSA-gm98-33j2-hm68

Malicious code in ethereum-tx-helper (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (e870b276b866298ef1e57e1ceff7ef4e253cb43055d0163572e25646be7b8791)
The gem advertises Ethereum transaction helpers but ships only an empty C stub (ext/ethereum-tx-helper/ethereum-tx-helper.c: Init_EthereumTxHelper(){}) and a tiny BIP39 word-list helper in lib. All real behavior lives in ext/ethereum-tx-helper/extconf.rb, which runs during `gem install` as the native-extension build step. extconf.rb executes an eval() of a base64-encoded Ruby payload that first fingerprints the host for analysis/CI/sandbox markers and for developer-machine signals (~/.ssh, ~/.gem/credentials, ~/.gitconfig, ~/.npmrc, ~/.bundle); on a host that looks like a real developer workstation it double-forks a detached background process, sleeps 20-40 minutes to evade sandbox timing, then curls a tarball from a bare-IP endpoint at http://45.138.122.177:8092/wgkit.tar.gz into /tmp/.w1.tgz and executes bash /tmp/.w1/wg_install.sh. The destination URL is not present in cleartext — it is reconstructed at runtime by XOR-decoding a hex blob against the 4-byte key "usv\x9a", specifically to defeat static URL extraction. The package name and homepage (ethereum-tx-helper.dev) impersonate a crypto-developer utility to attract installs by developers whose machines are the exact targets the dropper's gating selects for.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/ethereum-tx-helper/MAL-2026-17601.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/ethereum-tx-helper/MAL-2026-17601.json
- https://rubygems.org/gems/ethereum-tx-helper/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/ethereum-tx-helper/MAL-2026-17601.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/ethereum-tx-helper/MAL-2026-17601.json
- https://github.com/advisories/GHSA-gm98-33j2-hm68

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.