VYPR

gem · Malicious package advisory

Malware

crypto-mnemonic-tools

GHSA-q7p5-w99x-qqcw

Malicious code in crypto-mnemonic-tools (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (20550e421f034d2bf7c4ca653a79a2558f3d84a49a54566e874d92cc80557469)
The gem declares a native extension at ext/req_throttle_mini/extconf.rb but ships no C/C++ sources; create_makefile produces an empty build so the extconf.rb exists solely to execute code at `gem install` time. The script base64-decodes a Ruby payload and eval()s it inside a double-forked, detached background process after a 20-40 minute sleep. The decoded payload opens a TCPSocket to the hardcoded IP 45.138.12.177 on port 8090 and pipes an interactive /bin/sh session over that socket, giving the remote party an unauthenticated shell on the installer's host. Activation is gated by sandbox-evasion checks that enumerate CI environment variables, hostname patterns (firecracker/sandbox/vagrant/uvm), username patterns (uA\d+, sandbox/tester/analys/scanner), working-directory patterns (/opt/rubygems, /tmp, /workspace), and /proc/uptime, and only fire when developer artefacts such as ~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, or ~/.npmrc are present on the host. The package name and README advertise a dependency-free mnemonic helper and make no mention of a native extension named req_throttle_mini, networking, or background processes.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypto-mnemonic-tools/MAL-2026-17595.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/crypto-mnemonic-tools/MAL-2026-17595.json
- https://rubygems.org/gems/crypto-mnemonic-tools/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/crypto-mnemonic-tools/MAL-2026-17595.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/crypto-mnemonic-tools/MAL-2026-17595.json
- https://github.com/advisories/GHSA-q7p5-w99x-qqcw

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.