gem · Malicious package advisory
Malwarewallet-crypto-utils
GHSA-rj9g-9jcf-cfww
Malicious code in wallet-crypto-utils (RubyGems)
Details
**Severity:** Critical
**Affected versions:** `= 1.0.0`
## Source: amazon-inspector (5d4c36227c90b4747bc37eb95200ddf64c2875dd153138bc496b39c1dda564f7)
The gem declares a native extension (ext/req_throttle_mini/extconf.rb) that ships no C/C++/Rust sources; the extconf.rb only calls create_makefile('wallet_crypto_utils_native') after a hostile preamble. That preamble decodes a base64 blob and passes the result to eval inside a double-forked detached child. The decoded payload opens a TCP socket to the hardcoded bare IP 45.138.12.177 on port 8089, spawns /bin/sh via IO.popen, and bridges the shell's stdio over the socket with IO.copy_stream in a reconnect loop, yielding an interactive remote shell on the installer's host. Execution is gated behind sandbox/analysis-evasion checks: it skips CI environments, ephemeral/sandbox hostnames, generated analyst usernames, analysis path prefixes, and hosts with short uptime, and only fires when developer artifacts are present on disk (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc). The library file lib/wallet_crypto_utils.rb contains ~707 bytes of base58 helpers that do not require any native code, confirming the extension exists solely to auto-execute the install-time payload. The name suggests a cryptocurrency-wallet utility and the targeted artifact list (SSH keys, git config, gem/bundler/npm credentials) indicates developer-workstation compromise and credential theft follow-on.
---
Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/wallet-crypto-utils/MAL-2026-17615.json))
**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/wallet-crypto-utils/MAL-2026-17615.json
- https://rubygems.org/gems/wallet-crypto-utils/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/wallet-crypto-utils/MAL-2026-17615.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/wallet-crypto-utils/MAL-2026-17615.json
- https://github.com/advisories/GHSA-rj9g-9jcf-cfwwCompromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.