-= Per source details. Do not edit below this line.=-
The gem declares a native extension whose extconf.rb is the attack vehicle: the C source (ext/crypto-key-utils/crypto-key-utils.c) is a two-line empty Init stub, and create_makefile is only reached after a block of install-time logic. On gem install, extconf.rb runs sandbox/analysis evasion gates — skipping execution under CI, under analysis path prefixes (/tmp, /opt/rubygems, /workspace, /private/var/tmp), under generated usernames (uA\d+, sandbox/tester/analys/scanner), on ephemeral hostnames (uvm, firecracker, sandbox, vagrant), and when /proc/uptime is below 1800 seconds — and requires developer-host signals (presence of ~/.ssh, ~/.gem/credentials, ~/.npmrc, ~/.bundle). When the gates pass, it base64-decodes an embedded Ruby payload and double-forks it. The payload XOR-decodes a hardcoded URL (hex blob XORed with key "usv\x9a") resolving to http://45.138.127.77:8092/wgkit.tar.gz, sleeps a randomized 20–40 minutes, curls the tarball to /tmp/.w1.tgz over plain HTTP with no verification, extracts it, and executes bash /tmp/.w1/wg_install.sh. The lib/crypto-key-utils.rb entry is an unrelated BIP-39-style word list and does not implement the DER/PEM functionality the gem advertises.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021064",
"import_time": "2026-10-05T16:22:55.916180118Z",
"modified_time": "2026-10-05T15:58:56Z",
"sha256": "559eb6e590366fcb8968de4964d8eb9d61ad6149a1ce1d4696ff4f64bff1a214",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/crypto-key-utils/extconf.rb",
"sha256": "dc851aecce1c2ea9652daafb151e5821c8d75e6263b934a4dc98ea82869d3343",
"tlsh": "ca51cb56cb8395f54db1d0d044359412fb66bb0d6068ad64f3de0868bb5af2ac4f02fd"
},
{
"path": "ext/crypto-key-utils/crypto-key-utils.c",
"sha256": "7920c1543b84f5a68921718e7593becfeb6112bbdd306c55d87aabe0351ffbf7",
"tlsh": "e99002e5857864414044a2e2533582494191f8144d187e557b172555a5e02847d6a170"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/crypto-key-utils/MAL-2026-17594.json"