Date: 10/07/2026
Severity: High
Summary
Researchers identified 42 malicious RubyGems packages published by a threat actor known as Ghost Dev, targeting crypto and Web3 developers through typosquatting, brandjacking, and malicious utility packages. The packages deploy either a reverse shell or a cryptocurrency theft toolkit, with delayed execution and sandbox/CI environment detection. The crypto-stealing variant uses TLS interception, clipboard hijacking, wallet-data harvesting, seed/private-key theft, and browser hijacking to redirect cryptocurrency transactions and exfiltrate wallet secrets.
Indicators of Compromise (IOC) List
Domains/Urls | http://45.138.12.177:8080/wi/grab http://45.138.12.177:8080/w |
IP Address | 45.138.12.177 |
Hash | 387a778a6376b6c060516ce5c1191a61e075acfe3fb073e6e5cd78eeb96a95b3
549d35217f1e884634993ba6f13dd8e82091dd9f995a9ed0cb575958e63f073d
57a56ab47fa7f33147d4924b07e77d773515b4a06ca9ac090874209a9950f30b
b857fdf59db6948ea01643d935742904e9275572e63cd23331a9405483c6379c
33276fedf0632be39b4e8a646c520bfa081bb7e67dce52042da46bbbda16d440
075b6ac656aa414e2d21b9d1bc8b0fd030902202222e9d06a326fd80d7827ae6
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "http://45.138.12.177:8080/w" or url like "http://45.138.12.177:8080/w" or siteurl like "http://45.138.12.177:8080/w" or domainname like "http://45.138.12.177:8080/wi/grab" or url like "http://45.138.12.177:8080/wi/grab" or siteurl like "http://45.138.12.177:8080/wi/grab" |
Detection Query 2 : | dstipaddress IN ("45.138.12.177") or srcipaddress IN ("45.138.12.177") |
Detection Query 3 : | sha256hash IN ("57a56ab47fa7f33147d4924b07e77d773515b4a06ca9ac090874209a9950f30b","33276fedf0632be39b4e8a646c520bfa081bb7e67dce52042da46bbbda16d440","549d35217f1e884634993ba6f13dd8e82091dd9f995a9ed0cb575958e63f073d","387a778a6376b6c060516ce5c1191a61e075acfe3fb073e6e5cd78eeb96a95b3","b857fdf59db6948ea01643d935742904e9275572e63cd23331a9405483c6379c","075b6ac656aa414e2d21b9d1bc8b0fd030902202222e9d06a326fd80d7827ae6")
|
Reference:
Malicious Crypto Shell