VYPR

gem · Malicious package advisory

Malware

crypti-toolbox

GHSA-pv2w-f5fh-p8xw

Malicious code in crypti-toolbox (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (5ec4d5d5915335d90b2f18b45b050936fa5d2db9d176d7d081bd8c292c7c6795)
On `gem install`, the native extension script ext/crypti-toolbox/extconf.rb runs an environment-fingerprinting routine that bails out on CI runners, ephemeral/sandbox hostnames, generated or analysis-shaped usernames, analysis path prefixes (/opt/rubygems, /tmp, /workspace), low machine uptime, and hosts lacking developer artifacts (~/.ssh, ~/.gitconfig, ~/.gem/credentials). On hosts that pass those checks, the script base64-decodes a Ruby snippet and passes it to eval inside a double-forked, setsid-detached child that sleeps 20-40 minutes and then curls a tarball from http://45.138.122.177:8092/wgkit.tar.gz to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes the embedded wg_install.sh under bash. The destination URL is hidden as a hex string XORed with a 4-byte key, and the shell command is wrapped in a base64-encoded eval payload. There is no pin, hash, or signature on the fetched content, the destination is a bare IP unrelated to any declared publisher, and the sandbox-evasion and daemonization logic exist only to attack real developer workstations while hiding from analysis environments.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypti-toolbox/MAL-2026-17593.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypti-toolbox/MAL-2026-17593.json
- https://rubygems.org/gems/crypti-toolbox/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/crypti-toolbox/MAL-2026-17593.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/crypti-toolbox/MAL-2026-17593.json
- https://github.com/advisories/GHSA-pv2w-f5fh-p8xw

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.