VYPR

gem · Malicious package advisory

Malware

crylto-toolbox

GHSA-gxwc-r8hg-vg7r

Malicious code in crylto-toolbox (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (4362469cec139567ebe3c986d7f2eca2dda837ecff87373d14d9cfbedf81e6b0)
The gem's extconf.rb is not a native-extension build script. It contains a base64-encoded Ruby payload that, after gating on anti-analysis checks, downloads and executes an attacker-controlled shell script at install time. The anti-analysis gate inspects CI environment variables, hostname patterns (uvm/firecracker/sandbox/vagrant), username patterns (uA\d+, sandbox/tester/analys/scanner), working-directory prefixes (/tmp, /var/tmp, /opt/rubygems, /workspace), /proc/uptime (>1800s), and the presence of developer artifacts (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) to restrict execution to real developer machines. When the gate passes, extconf.rb forks a detached process that sleeps 20-40 minutes, then reconstructs a URL by XOR-decoding a hex blob with key 'usv\x9a' resolving to http://45.138.12.177:8092/wgkit.tar.gz, downloads the archive to /tmp/.w1.tgz with no TLS and no integrity check, extracts it, and runs bash /tmp/.w1/wg_install.sh via system(). The package name is a typo of 'crypto-toolbox'. The combination of obfuscated URL reconstruction, bare-IP plaintext HTTP delivery, detached delayed execution, sandbox-evasion gating keyed on developer-only artifacts, and execution of arbitrary attacker-supplied bash during `gem install` is an install-time dropper on the installer's host.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crylto-toolbox/MAL-2026-17591.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crylto-toolbox/MAL-2026-17591.json
- https://rubygems.org/gems/crylto-toolbox/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/crylto-toolbox/MAL-2026-17591.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/crylto-toolbox/MAL-2026-17591.json
- https://github.com/advisories/GHSA-gxwc-r8hg-vg7r

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.