Source: amazon-inspector (5ec4d5d5915335d90b2f18b45b050936fa5d2db9d176d7d081bd8c292c7c6795)
On gem install, the native extension script ext/crypti-toolbox/extconf.rb runs an environment-fingerprinting routine that bails out on CI runners, ephemeral/sandbox hostnames, generated or analysis-shaped usernames, analysis path prefixes (/opt/rubygems, /tmp, /workspace), low machine uptime, and hosts lacking developer artifacts (~/.ssh, ~/.gitconfig, ~/.gem/credentials). On hosts that pass those checks, the script base64-decodes a Ruby snippet and passes it to eval inside a double-forked, setsid-detached child that sleeps 20-40 minutes and then curls a tarball from http://45.138.122.177:8092/wgkit.tar.gz to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes the embedded wg_install.sh under bash. The destination URL is hidden as a hex string XORed with a 4-byte key, and the shell command is wrapped in a base64-encoded eval payload. There is no pin, hash, or signature on the fetched content, the destination is a bare IP unrelated to any declared publisher, and the sandbox-evasion and daemonization logic exist only to attack real developer workstations while hiding from analysis environments.
Credit: OpenSSF (source)
References
Source: amazon-inspector (5ec4d5d5915335d90b2f18b45b050936fa5d2db9d176d7d081bd8c292c7c6795)
On
gem install, the native extension script ext/crypti-toolbox/extconf.rb runs an environment-fingerprinting routine that bails out on CI runners, ephemeral/sandbox hostnames, generated or analysis-shaped usernames, analysis path prefixes (/opt/rubygems, /tmp, /workspace), low machine uptime, and hosts lacking developer artifacts (~/.ssh, ~/.gitconfig, ~/.gem/credentials). On hosts that pass those checks, the script base64-decodes a Ruby snippet and passes it to eval inside a double-forked, setsid-detached child that sleeps 20-40 minutes and then curls a tarball from http://45.138.122.177:8092/wgkit.tar.gz to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes the embedded wg_install.sh under bash. The destination URL is hidden as a hex string XORed with a 4-byte key, and the shell command is wrapped in a base64-encoded eval payload. There is no pin, hash, or signature on the fetched content, the destination is a bare IP unrelated to any declared publisher, and the sandbox-evasion and daemonization logic exist only to attack real developer workstations while hiding from analysis environments.Credit: OpenSSF (source)
References