VYPR

gem · Malicious package advisory

Malware

solaan-ruby

GHSA-vwg4-2hf7-g55g

Malicious code in solaan-ruby (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (e44549858fa90854aa5c3acae5440714ef5271cabb67243d4c82713ca3c108f7)
The gem's native-extension build script (extconf.rb) carries a base64-encoded Ruby payload that executes at `gem install` time via the standard mkmf build hook. The accompanying C source is a 2-line empty stub, so building a native extension is not the real purpose of the file — the gem exists to run the embedded payload. The payload XOR-reconstructs a URL pointing at the hardcoded bare-IP endpoint http://45.138.12.177:8092/wgkit.tar.gz, curls the tarball to /tmp/.w1.tgz with no integrity check, extracts it to /tmp/.w1, and runs `bash /tmp/.w1/wg_install.sh`, giving the operator of that IP arbitrary code execution on the installer's host. Execution is gated by evasion checks that abort on CI environments, hostnames matching uvm/firecracker/sandbox/vagrant, usernames matching scanner patterns, working directories under /tmp or /opt/rubygems, and `/proc/uptime` under 1800 seconds, and only proceeds when developer artifacts are present on disk (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle). The dropper additionally forks a detached child and sleeps a randomized 20–40 minutes before the fetch to evade install-time observation. The combination of obfuscated remote URL, bare-IP HTTP source, pipe-to-bash execution, sandbox evasion, and developer-workstation targeting is an install-time remote code execution attack against developer machines that install the gem.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/solaan-ruby/MAL-2026-17610.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/solaan-ruby/MAL-2026-17610.json
- https://rubygems.org/gems/solaan-ruby/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/solaan-ruby/MAL-2026-17610.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/solaan-ruby/MAL-2026-17610.json
- https://github.com/advisories/GHSA-vwg4-2hf7-g55g

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.