gem · Malicious package advisory
Malwarecrypti-toolbox
GHSA-pv2w-f5fh-p8xw
Malicious code in crypti-toolbox (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (5ec4d5d5915335d90b2f18b45b050936fa5d2db9d176d7d081bd8c292c7c6795) On `gem install`, the native extension script ext/crypti-toolbox/extconf.rb runs an environment-fingerprinting routine that bails out on CI runners, ephemeral/sandbox hostnames, generated or analysis-shaped usernames, analysis path prefixes (/opt/rubygems, /tmp, /workspace), low machine uptime, and hosts lacking developer artifacts (~/.ssh, ~/.gitconfig, ~/.gem/credentials). On hosts that pass those checks, the script base64-decodes a Ruby snippet and passes it to eval inside a double-forked, setsid-detached child that sleeps 20-40 minutes and then curls a tarball from http://45.138.122.177:8092/wgkit.tar.gz to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes the embedded wg_install.sh under bash. The destination URL is hidden as a hex string XORed with a 4-byte key, and the shell command is wrapped in a base64-encoded eval payload. There is no pin, hash, or signature on the fetched content, the destination is a bare IP unrelated to any declared publisher, and the sandbox-evasion and daemonization logic exist only to attack real developer workstations while hiding from analysis environments. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypti-toolbox/MAL-2026-17593.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypti-toolbox/MAL-2026-17593.json - https://rubygems.org/gems/crypti-toolbox/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/crypti-toolbox/MAL-2026-17593.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/crypti-toolbox/MAL-2026-17593.json - https://github.com/advisories/GHSA-pv2w-f5fh-p8xw
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.