MAL-2026-17588

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/blockchain-sync-utils/MAL-2026-17588.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17588
Published
2026-10-05T15:59:31Z
Modified
2026-10-05T16:30:07Z
Summary
Malicious code in blockchain-sync-utils (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (78a8b7d5a56c33e17464f8129001559f02bd245cd299cb8cb07ccc334eb5af65)

The gem's native-extension build script (ext/.../extconf.rb) is a dropper rather than a real build step. The accompanying C source is a no-op stub, so the extension exists only to run install-time code. The script decodes a base64-wrapped Ruby payload and eval()s it inside a detached double-fork (Process.setsid), after gating on anti-analysis checks (CI environment variables, hostname regex, /proc/uptime greater than 1800 seconds, jittered sleep) and on the presence of developer-credential artifacts on the host (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) so the payload only fires on real developer workstations. The payload's destination URL is stored as a hex blob XORed with a 4-byte key and resolves to http://45.138.122.177:8092/wgkit.tar.gz; the decoded command curls that tarball to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh. Installing the gem runs attacker-controlled shell code on the installer's machine from a bare-IP endpoint over plain HTTP, with no pinning or integrity check and with explicit sandbox evasion.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021068",
            "import_time": "2026-10-05T16:22:56.279235652Z",
            "modified_time": "2026-10-05T15:59:31Z",
            "sha256": "78a8b7d5a56c33e17464f8129001559f02bd245cd299cb8cb07ccc334eb5af65",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / blockchain-sync-utils

Package

Name
blockchain-sync-utils
Purl
pkg:gem/blockchain-sync-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/blockchain-sync-utils/extconf.rb",
            "sha256": "4c4f9bbbc7fb381c1185255fef4698474ba78f8758aed6618e59933678f9cad0",
            "tlsh": "ac51da568b8395f54db1d0d004395412fb66bb0d6068ac64f3de0868bb4af2ac4f02fd"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/blockchain-sync-utils/MAL-2026-17588.json"