gem · Malicious package advisory
Malwarecrylto-toolbox
GHSA-gxwc-r8hg-vg7r
Malicious code in crylto-toolbox (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (4362469cec139567ebe3c986d7f2eca2dda837ecff87373d14d9cfbedf81e6b0) The gem's extconf.rb is not a native-extension build script. It contains a base64-encoded Ruby payload that, after gating on anti-analysis checks, downloads and executes an attacker-controlled shell script at install time. The anti-analysis gate inspects CI environment variables, hostname patterns (uvm/firecracker/sandbox/vagrant), username patterns (uA\d+, sandbox/tester/analys/scanner), working-directory prefixes (/tmp, /var/tmp, /opt/rubygems, /workspace), /proc/uptime (>1800s), and the presence of developer artifacts (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) to restrict execution to real developer machines. When the gate passes, extconf.rb forks a detached process that sleeps 20-40 minutes, then reconstructs a URL by XOR-decoding a hex blob with key 'usv\x9a' resolving to http://45.138.12.177:8092/wgkit.tar.gz, downloads the archive to /tmp/.w1.tgz with no TLS and no integrity check, extracts it, and runs bash /tmp/.w1/wg_install.sh via system(). The package name is a typo of 'crypto-toolbox'. The combination of obfuscated URL reconstruction, bare-IP plaintext HTTP delivery, detached delayed execution, sandbox-evasion gating keyed on developer-only artifacts, and execution of arbitrary attacker-supplied bash during `gem install` is an install-time dropper on the installer's host. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crylto-toolbox/MAL-2026-17591.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crylto-toolbox/MAL-2026-17591.json - https://rubygems.org/gems/crylto-toolbox/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/crylto-toolbox/MAL-2026-17591.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/crylto-toolbox/MAL-2026-17591.json - https://github.com/advisories/GHSA-gxwc-r8hg-vg7r
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.