-= Per source details. Do not edit below this line.=-
The gem declares a native C extension whose shipped source (ext/bip39-wordlist-utils/bip39-wordlist-utils.c) is an empty Init stub, so gem install executes extconf.rb purely as a lifecycle hook. extconf.rb decodes a base64 Ruby blob and evals it; the eval'd payload XOR-reconstructs the URL http://45.138.127.177:8092/wgkit.tar.gz (bare IP, plain HTTP, unrelated to any BIP39 purpose), double-forks a detached child, uses curl to download the tarball to /tmp/.w1.tgz, extracts to /tmp/.w1, and executes wg_install.sh as the installing user. Execution is gated by developer-targeting evasion checks: it aborts when CI env vars are set, when hostname matches sandbox/firecracker/vagrant, when the username matches scanner/analys/sandbox/tester, when CWD is under /tmp, /var/tmp, /opt/rubygems, or /workspace, or when /proc/uptime is under 1800 seconds, and only proceeds when developer artifacts (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc) are present. The payload then sleeps 1200-2400 seconds before firing. After the dropper logic, extconf.rb calls create_makefile to let the gem install appear to succeed. No legitimate build toolchain probing (mkmf have_header, pkg_config, try_run) is performed and no real native source is compiled.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021067",
"import_time": "2026-10-05T16:22:56.178211868Z",
"modified_time": "2026-10-05T15:59:22Z",
"sha256": "4b3ac427b6e4032e434211228b95b76c556690f86e9e3ba44134e2b8525253c5",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/bip39-wordlist-utils/extconf.rb",
"sha256": "617eaa534cbc18e745debc3ae8ba4602862905ffe8f0fe4a24f69d5b57493f73",
"tlsh": "ba51da568b8395f64db1d0d004355412fb66bb0d6068ac64f3de0868bb4af2ac4f02fd"
},
{
"path": "ext/bip39-wordlist-utils/bip39-wordlist-utils.c",
"sha256": "04536b1c565dc0072ea0048f4ca448f522369a7d903a41962932d20fe1de56d3",
"tlsh": "6a90228088380c030080a2a30332000200a0f0200c2032003a030380e0e028038ae030"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/bip39-wordlist-utils/MAL-2026-17581.json"