MAL-2026-17597

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17597
Published
2026-10-05T16:00:11Z
Modified
2026-10-05T16:30:09Z
Summary
Malicious code in eth-address-utils (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (8ed9d372d4fc694697be41c22e7c4d02d873e53e16bde2336069787b7b961ce2)

The gem advertises itself as an Ethereum address utility library but its extconf.rb (auto-executed by gem install) carries a base64-encoded payload that is decoded and passed to eval inside a double-forked, detached background process. The decoded payload sleeps 20-40 minutes and then opens a TCPSocket to the hardcoded remote host 45.138.12.177 on port 8090, bridging the socket to IO.popen(['/bin/sh'],'r+') — a reverse shell giving the operator of that IP full remote code execution on the installer's host under the installing user's privileges. The extension declares a native component named req_throttle_mini but ships no corresponding C sources; create_makefile is appended only as camouflage. Payload execution is gated by anti-analysis checks that skip CI environments, ephemeral/sandbox hostnames (uvm/firecracker/sandbox/vagrant), synthetic analyst usernames (sandbox/tester/analys/scanner), build paths under /tmp, /opt/rubygems, /workspace, systems with uptime under 1800 seconds, and hosts lacking developer-identity artifacts such as ~/.ssh, ~/.gitconfig, ~/.gem/credentials, or ~/.bundle — so only real developer workstations are compromised. The library name, the fake native-extension stub, and the sandbox evasion together confirm this is a disguised remote-access implant, not a build helper.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021073",
            "import_time": "2026-10-05T16:22:56.645614866Z",
            "modified_time": "2026-10-05T16:00:11Z",
            "sha256": "8ed9d372d4fc694697be41c22e7c4d02d873e53e16bde2336069787b7b961ce2",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / eth-address-utils

Package

Name
eth-address-utils
Purl
pkg:gem/eth-address-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/req_throttle_mini/extconf.rb",
            "sha256": "76b5351cf8c341b13fb7b11f20ab8625051cab459ec83c73848cf4f438e60b2d",
            "tlsh": "6e518855cf8359e516a1c0c0457d8012faa3ab0a50646875f3ee0868ff59b76c1f12fe"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json"