MAL-2026-17598

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/eth-keystore-utils/MAL-2026-17598.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17598
Published
2026-10-05T15:59:56Z
Modified
2026-10-05T16:30:08Z
Summary
Malicious code in eth-keystore-utils (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (cd660255e3a3483ed89e81f30c696390f8b182a891f8f1fb7e4c1cbb3b52eb32)

The gem advertises itself as an Ethereum keystore helper but ships a native extension (ext/req_throttle_mini/extconf.rb) whose sole purpose is to execute a malicious payload during gem install. The extconf script base64-decodes an embedded Ruby payload and evals it inside a double-forked, detached child process, then writes an empty Makefile via create_makefile with no C sources present. The decoded payload opens a TCP connection to the hardcoded bare-IP C2 at 45.138.12.177:8090, pipes the socket to /bin/sh via IO.popen and IO.copy_stream in both directions, and reconnects on failure in a loop, giving the operator a persistent remote shell on the installer's host. The dropper is gated by anti-analysis checks: it refuses to fire inside CI, ephemeral or sandbox-shaped hostnames, generated usernames, or analysis path prefixes, requires the presence of developer secrets (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) and sufficient machine uptime, and sleeps 20–40 minutes after detaching before executing to evade install-time scanners. The lib/ module is a thin JSON reader that serves as cover; the native extension ships no real build sources. Package naming targets Ethereum developers likely to hold wallet material and cloud/VCS credentials on their workstations.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021071",
            "import_time": "2026-10-05T16:22:56.506545449Z",
            "modified_time": "2026-10-05T15:59:56Z",
            "sha256": "cd660255e3a3483ed89e81f30c696390f8b182a891f8f1fb7e4c1cbb3b52eb32",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / eth-keystore-utils

Package

Name
eth-keystore-utils
Purl
pkg:gem/eth-keystore-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/req_throttle_mini/extconf.rb",
            "sha256": "6e2d9cf381d1bab758fc524de1754c8a4cff0bdd8754091156143a38fadcef2d",
            "tlsh": "6a518855cf8359e51ae1c0c0457d8012faa3ab0a50646875f3ee0868ff59b6ac1f12fe"
        },
        {
            "path": "metadata.yaml",
            "sha256": "c0e649a652846494a52e0342daaf13c0a3162103be4183e194da9a89fc95803a",
            "tlsh": "18217fc1a6c7fc37fd05e1d5a4402343a7b3d50c7e692901699741c5039a1e9a71b161"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/eth-keystore-utils/MAL-2026-17598.json"