-= Per source details. Do not edit below this line.=-
The gem's native-extension build script (ext/.../extconf.rb) is a dropper rather than a real build step. The accompanying C source is a no-op stub, so the extension exists only to run install-time code. The script decodes a base64-wrapped Ruby payload and eval()s it inside a detached double-fork (Process.setsid), after gating on anti-analysis checks (CI environment variables, hostname regex, /proc/uptime greater than 1800 seconds, jittered sleep) and on the presence of developer-credential artifacts on the host (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) so the payload only fires on real developer workstations. The payload's destination URL is stored as a hex blob XORed with a 4-byte key and resolves to http://45.138.122.177:8092/wgkit.tar.gz; the decoded command curls that tarball to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh. Installing the gem runs attacker-controlled shell code on the installer's machine from a bare-IP endpoint over plain HTTP, with no pinning or integrity check and with explicit sandbox evasion.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021068",
"import_time": "2026-10-05T16:22:56.279235652Z",
"modified_time": "2026-10-05T15:59:31Z",
"sha256": "78a8b7d5a56c33e17464f8129001559f02bd245cd299cb8cb07ccc334eb5af65",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/blockchain-sync-utils/extconf.rb",
"sha256": "4c4f9bbbc7fb381c1185255fef4698474ba78f8758aed6618e59933678f9cad0",
"tlsh": "ac51da568b8395f54db1d0d004395412fb66bb0d6068ac64f3de0868bb4af2ac4f02fd"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/blockchain-sync-utils/MAL-2026-17588.json"