VYPR

gem · Malicious package advisory

Malware

tron-rb

GHSA-pfxv-45h9-p87w

Malicious code in tron-rb (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (a483b2d8f8273b5dca3a95d449d762cdfe9d79e8aea485cb89673c469e4cda6f)
The gem advertises TRON protocol helpers but ships only a 45-byte empty C stub (ext/tron-rb/tron-rb.c) and a hardcoded word-list library module; its sole operative code path is in ext/tron-rb/extconf.rb. On gem install, extconf.rb base64-decodes and eval's a Ruby payload that reconstructs a destination URL by XOR'ing a hex byte array against a 4-byte key, resolving to http://45.138.17.177:8092/wgkit.tar.gz. Before firing, the payload applies sandbox/analysis evasion: it bails out on CI environment variables, ephemeral hostnames matching uvm/firecracker/sandbox/vagrant, generated-looking usernames (uA\d+/sandbox/tester/analys/scanner), analysis working-directory prefixes (/opt/rubygems, /tmp/, /workspace/), machine uptime under 30 minutes, and hosts missing developer artifacts (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle). If the gating passes, it double-forks a detached, I/O-nulled process that sleeps 20-40 minutes, then runs curl against the bare-IP URL to download /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh - all before create_makefile is called. The declared native extension is a cover story: there is no real C source for the stub to build, so the extension exists solely to trigger extconf.rb execution during install. Indicators: 45.138.17.177:8092, /tmp/.w1.tgz, /tmp/.w1/wg_install.sh.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/tron-rb/MAL-2026-17611.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/tron-rb/MAL-2026-17611.json
- https://rubygems.org/gems/tron-rb/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/tron-rb/MAL-2026-17611.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/advisories/GHSA-pfxv-45h9-p87w

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.