-= Per source details. Do not edit below this line.=-
The gem advertises itself as an Ethereum keystore helper but ships a native extension (ext/req_throttle_mini/extconf.rb) whose sole purpose is to execute a malicious payload during gem install. The extconf script base64-decodes an embedded Ruby payload and evals it inside a double-forked, detached child process, then writes an empty Makefile via create_makefile with no C sources present. The decoded payload opens a TCP connection to the hardcoded bare-IP C2 at 45.138.12.177:8090, pipes the socket to /bin/sh via IO.popen and IO.copy_stream in both directions, and reconnects on failure in a loop, giving the operator a persistent remote shell on the installer's host. The dropper is gated by anti-analysis checks: it refuses to fire inside CI, ephemeral or sandbox-shaped hostnames, generated usernames, or analysis path prefixes, requires the presence of developer secrets (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) and sufficient machine uptime, and sleeps 20–40 minutes after detaching before executing to evade install-time scanners. The lib/ module is a thin JSON reader that serves as cover; the native extension ships no real build sources. Package naming targets Ethereum developers likely to hold wallet material and cloud/VCS credentials on their workstations.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021071",
"import_time": "2026-10-05T16:22:56.506545449Z",
"modified_time": "2026-10-05T15:59:56Z",
"sha256": "cd660255e3a3483ed89e81f30c696390f8b182a891f8f1fb7e4c1cbb3b52eb32",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/req_throttle_mini/extconf.rb",
"sha256": "6e2d9cf381d1bab758fc524de1754c8a4cff0bdd8754091156143a38fadcef2d",
"tlsh": "6a518855cf8359e51ae1c0c0457d8012faa3ab0a50646875f3ee0868ff59b6ac1f12fe"
},
{
"path": "metadata.yaml",
"sha256": "c0e649a652846494a52e0342daaf13c0a3162103be4183e194da9a89fc95803a",
"tlsh": "18217fc1a6c7fc37fd05e1d5a4402343a7b3d50c7e692901699741c5039a1e9a71b161"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/eth-keystore-utils/MAL-2026-17598.json"