MAL-2026-17581

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/bip39-wordlist-utils/MAL-2026-17581.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17581
Published
2026-10-05T15:59:22Z
Modified
2026-10-05T16:30:08Z
Summary
Malicious code in bip39-wordlist-utils (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4b3ac427b6e4032e434211228b95b76c556690f86e9e3ba44134e2b8525253c5)

The gem declares a native C extension whose shipped source (ext/bip39-wordlist-utils/bip39-wordlist-utils.c) is an empty Init stub, so gem install executes extconf.rb purely as a lifecycle hook. extconf.rb decodes a base64 Ruby blob and evals it; the eval'd payload XOR-reconstructs the URL http://45.138.127.177:8092/wgkit.tar.gz (bare IP, plain HTTP, unrelated to any BIP39 purpose), double-forks a detached child, uses curl to download the tarball to /tmp/.w1.tgz, extracts to /tmp/.w1, and executes wg_install.sh as the installing user. Execution is gated by developer-targeting evasion checks: it aborts when CI env vars are set, when hostname matches sandbox/firecracker/vagrant, when the username matches scanner/analys/sandbox/tester, when CWD is under /tmp, /var/tmp, /opt/rubygems, or /workspace, or when /proc/uptime is under 1800 seconds, and only proceeds when developer artifacts (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc) are present. The payload then sleeps 1200-2400 seconds before firing. After the dropper logic, extconf.rb calls create_makefile to let the gem install appear to succeed. No legitimate build toolchain probing (mkmf have_header, pkg_config, try_run) is performed and no real native source is compiled.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021067",
            "import_time": "2026-10-05T16:22:56.178211868Z",
            "modified_time": "2026-10-05T15:59:22Z",
            "sha256": "4b3ac427b6e4032e434211228b95b76c556690f86e9e3ba44134e2b8525253c5",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / bip39-wordlist-utils

Package

Name
bip39-wordlist-utils
Purl
pkg:gem/bip39-wordlist-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/bip39-wordlist-utils/extconf.rb",
            "sha256": "617eaa534cbc18e745debc3ae8ba4602862905ffe8f0fe4a24f69d5b57493f73",
            "tlsh": "ba51da568b8395f64db1d0d004355412fb66bb0d6068ac64f3de0868bb4af2ac4f02fd"
        },
        {
            "path": "ext/bip39-wordlist-utils/bip39-wordlist-utils.c",
            "sha256": "04536b1c565dc0072ea0048f4ca448f522369a7d903a41962932d20fe1de56d3",
            "tlsh": "6a90228088380c030080a2a30332000200a0f0200c2032003a030380e0e028038ae030"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/bip39-wordlist-utils/MAL-2026-17581.json"