-= Per source details. Do not edit below this line.=-
The gem's ext/base58-check-helper/extconf.rb runs during gem install and, before invoking create_makefile, performs anti-analysis gating: it skips execution when CI environment variables are present, when the hostname looks ephemeral, when the username looks synthetic, when the working path matches /tmp, /opt/rubygems, or /workspace, when machine uptime is under 1800 seconds, or when common developer dotfiles are absent. When those checks indicate a real developer workstation (presence of ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, or ~/.bundle), it base64-decodes an embedded Ruby payload and eval's it inside a double-forked, Process.setsid-daemonized child. The decoded payload reconstructs a URL by XOR-ing a hex blob against the key bytes of "usv\x9a", then uses curl to download an unpinned tarball to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh. The native source accompanying the extension is a two-line empty stub, so the extension exists solely as a vehicle for the dropper. The combination of base64+XOR obfuscation, hidden /tmp staging, developer-machine targeting, sandbox/CI evasion, and daemonized execution of remote shell content is a credential-stealer dropper fingerprint.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021065",
"import_time": "2026-10-05T16:22:56.007963039Z",
"modified_time": "2026-10-05T15:59:05Z",
"sha256": "1fe852f0d3458d12270208daca66a3f83046929fcf8434d556261f89d578c06a",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/base58-check-helper/extconf.rb",
"sha256": "9a54489501c40f4b44b8d6d47411b93d7ef51472d6720df40111c17ae4de8445",
"tlsh": "9851ca568b8395f64db1d0d044755412fb667b0d6068ac64f3de0868fb5af2ac4f02fd"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/base58-check-helper/MAL-2026-17580.json"