MAL-2026-17580

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/base58-check-helper/MAL-2026-17580.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17580
Published
2026-10-05T15:59:05Z
Modified
2026-10-05T16:30:09Z
Summary
Malicious code in base58-check-helper (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1fe852f0d3458d12270208daca66a3f83046929fcf8434d556261f89d578c06a)

The gem's ext/base58-check-helper/extconf.rb runs during gem install and, before invoking create_makefile, performs anti-analysis gating: it skips execution when CI environment variables are present, when the hostname looks ephemeral, when the username looks synthetic, when the working path matches /tmp, /opt/rubygems, or /workspace, when machine uptime is under 1800 seconds, or when common developer dotfiles are absent. When those checks indicate a real developer workstation (presence of ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, or ~/.bundle), it base64-decodes an embedded Ruby payload and eval's it inside a double-forked, Process.setsid-daemonized child. The decoded payload reconstructs a URL by XOR-ing a hex blob against the key bytes of "usv\x9a", then uses curl to download an unpinned tarball to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh. The native source accompanying the extension is a two-line empty stub, so the extension exists solely as a vehicle for the dropper. The combination of base64+XOR obfuscation, hidden /tmp staging, developer-machine targeting, sandbox/CI evasion, and daemonized execution of remote shell content is a credential-stealer dropper fingerprint.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021065",
            "import_time": "2026-10-05T16:22:56.007963039Z",
            "modified_time": "2026-10-05T15:59:05Z",
            "sha256": "1fe852f0d3458d12270208daca66a3f83046929fcf8434d556261f89d578c06a",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / base58-check-helper

Package

Name
base58-check-helper
Purl
pkg:gem/base58-check-helper

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/base58-check-helper/extconf.rb",
            "sha256": "9a54489501c40f4b44b8d6d47411b93d7ef51472d6720df40111c17ae4de8445",
            "tlsh": "9851ca568b8395f64db1d0d044755412fb667b0d6068ac64f3de0868fb5af2ac4f02fd"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/base58-check-helper/MAL-2026-17580.json"