VYPR

gem · Malicious package advisory

Malware

etheremu.rb

GHSA-r55r-pjq3-j9f4

Malicious code in etheremu.rb (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (a82ac5d3f021ab23f4f461181f4150c12d672ef421b6f80c10dd8a307178442e)
The gem's extconf.rb, executed automatically during `gem install`, contains a base64-encoded Ruby payload that is decoded and eval'd inside a detached forked process. The payload XOR-decodes a hardcoded bare-IP URL (http://45.138.12.177:8092/wgkit.tar.gz), downloads a tarball to /tmp/.w1.tgz over plain HTTP with no pinning or verification, extracts it, and executes the enclosed wg_install.sh via bash. The accompanying native extension C source is an empty stub whose Init function is a no-op, so the extension exists solely as a vehicle to trigger the dropper at install time. The dropper is wrapped in extensive anti-analysis gating: it exits early if CI environment variables are set, if the hostname matches sandbox/firecracker/vagrant patterns, if the username looks auto-generated or contains strings like 'sandbox', 'tester', 'analys', or 'scanner', if the current working directory is under /tmp, /var/tmp, /opt/rubygems, or /workspace, if machine uptime is under 1800 seconds, or if no developer dot-files are present. It further sleeps 20-40 minutes before firing. Execution is gated on the presence of ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, or ~/.bundle in the installer's home directory, selecting victims whose machines hold SSH keys and rubygems/npm/git publisher credentials for downstream harvesting by the fetched wg_install.sh stage.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/etheremu.rb/MAL-2026-17600.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/etheremu.rb/MAL-2026-17600.json
- https://rubygems.org/gems/etheremu.rb/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/etheremu.rb/MAL-2026-17600.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/etheremu.rb/MAL-2026-17600.json
- https://github.com/advisories/GHSA-r55r-pjq3-j9f4

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.