gem · Malicious package advisory
Malwarecrypto-mnemonic-tools
GHSA-q7p5-w99x-qqcw
Malicious code in crypto-mnemonic-tools (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (20550e421f034d2bf7c4ca653a79a2558f3d84a49a54566e874d92cc80557469) The gem declares a native extension at ext/req_throttle_mini/extconf.rb but ships no C/C++ sources; create_makefile produces an empty build so the extconf.rb exists solely to execute code at `gem install` time. The script base64-decodes a Ruby payload and eval()s it inside a double-forked, detached background process after a 20-40 minute sleep. The decoded payload opens a TCPSocket to the hardcoded IP 45.138.12.177 on port 8090 and pipes an interactive /bin/sh session over that socket, giving the remote party an unauthenticated shell on the installer's host. Activation is gated by sandbox-evasion checks that enumerate CI environment variables, hostname patterns (firecracker/sandbox/vagrant/uvm), username patterns (uA\d+, sandbox/tester/analys/scanner), working-directory patterns (/opt/rubygems, /tmp, /workspace), and /proc/uptime, and only fire when developer artefacts such as ~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, or ~/.npmrc are present on the host. The package name and README advertise a dependency-free mnemonic helper and make no mention of a native extension named req_throttle_mini, networking, or background processes. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypto-mnemonic-tools/MAL-2026-17595.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypto-mnemonic-tools/MAL-2026-17595.json - https://rubygems.org/gems/crypto-mnemonic-tools/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/crypto-mnemonic-tools/MAL-2026-17595.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/crypto-mnemonic-tools/MAL-2026-17595.json - https://github.com/advisories/GHSA-q7p5-w99x-qqcw
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.