-= Per source details. Do not edit below this line.=-
The gem advertises itself as an Ethereum address utility library but its extconf.rb (auto-executed by gem install) carries a base64-encoded payload that is decoded and passed to eval inside a double-forked, detached background process. The decoded payload sleeps 20-40 minutes and then opens a TCPSocket to the hardcoded remote host 45.138.12.177 on port 8090, bridging the socket to IO.popen(['/bin/sh'],'r+') — a reverse shell giving the operator of that IP full remote code execution on the installer's host under the installing user's privileges. The extension declares a native component named req_throttle_mini but ships no corresponding C sources; create_makefile is appended only as camouflage. Payload execution is gated by anti-analysis checks that skip CI environments, ephemeral/sandbox hostnames (uvm/firecracker/sandbox/vagrant), synthetic analyst usernames (sandbox/tester/analys/scanner), build paths under /tmp, /opt/rubygems, /workspace, systems with uptime under 1800 seconds, and hosts lacking developer-identity artifacts such as ~/.ssh, ~/.gitconfig, ~/.gem/credentials, or ~/.bundle — so only real developer workstations are compromised. The library name, the fake native-extension stub, and the sandbox evasion together confirm this is a disguised remote-access implant, not a build helper.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021073",
"import_time": "2026-10-05T16:22:56.645614866Z",
"modified_time": "2026-10-05T16:00:11Z",
"sha256": "8ed9d372d4fc694697be41c22e7c4d02d873e53e16bde2336069787b7b961ce2",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/req_throttle_mini/extconf.rb",
"sha256": "76b5351cf8c341b13fb7b11f20ab8625051cab459ec83c73848cf4f438e60b2d",
"tlsh": "6e518855cf8359e516a1c0c0457d8012faa3ab0a50646875f3ee0868ff59b76c1f12fe"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/eth-address-utils/MAL-2026-17597.json"