Malicious Crypto Shell Packages Target RubyGems

    Date: 10/07/2026

    Severity: High

    Summary

    Researchers identified 42 malicious RubyGems packages published by a threat actor known as Ghost Dev, targeting crypto and Web3 developers through typosquatting, brandjacking, and malicious utility packages. The packages deploy either a reverse shell or a cryptocurrency theft toolkit, with delayed execution and sandbox/CI environment detection. The crypto-stealing variant uses TLS interception, clipboard hijacking, wallet-data harvesting, seed/private-key theft, and browser hijacking to redirect cryptocurrency transactions and exfiltrate wallet secrets.  

    Indicators of Compromise (IOC) List 

    Domains/Urls

    http://45.138.12.177:8080/wi/grab

    http://45.138.12.177:8080/w

    IP Address

    45.138.12.177

    Hash

    387a778a6376b6c060516ce5c1191a61e075acfe3fb073e6e5cd78eeb96a95b3

    549d35217f1e884634993ba6f13dd8e82091dd9f995a9ed0cb575958e63f073d

    57a56ab47fa7f33147d4924b07e77d773515b4a06ca9ac090874209a9950f30b

    b857fdf59db6948ea01643d935742904e9275572e63cd23331a9405483c6379c

    33276fedf0632be39b4e8a646c520bfa081bb7e67dce52042da46bbbda16d440

    075b6ac656aa414e2d21b9d1bc8b0fd030902202222e9d06a326fd80d7827ae6

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "http://45.138.12.177:8080/w" or url like "http://45.138.12.177:8080/w" or siteurl like "http://45.138.12.177:8080/w" or domainname like "http://45.138.12.177:8080/wi/grab" or url like "http://45.138.12.177:8080/wi/grab" or siteurl like "http://45.138.12.177:8080/wi/grab"

    Detection Query 2 :

    dstipaddress IN ("45.138.12.177") or srcipaddress IN ("45.138.12.177")

    Detection Query 3 :

    sha256hash IN ("57a56ab47fa7f33147d4924b07e77d773515b4a06ca9ac090874209a9950f30b","33276fedf0632be39b4e8a646c520bfa081bb7e67dce52042da46bbbda16d440","549d35217f1e884634993ba6f13dd8e82091dd9f995a9ed0cb575958e63f073d","387a778a6376b6c060516ce5c1191a61e075acfe3fb073e6e5cd78eeb96a95b3","b857fdf59db6948ea01643d935742904e9275572e63cd23331a9405483c6379c","075b6ac656aa414e2d21b9d1bc8b0fd030902202222e9d06a326fd80d7827ae6")

    Reference:    

    Malicious Crypto Shell                                                 


    Tags

    MalwareThreat ActorCredential HarvestingSupply chain attackreverse shellcryptocurrencyClipboard hijackingBrowser HijackingExfiltration

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags