-= Per source details. Do not edit below this line.=-
The gem presents itself as a BIP32/mnemonic derivation helper but ships only a wordlist stub and a 56-byte empty C file (ext/hdkey-derive-helper/hdkey-derive-helper.c, body void Init_HdkeyDeriveHelper(void) {}) registered as a native extension. Because RubyGems auto-executes extconf.rb during gem install, the extension exists solely as an execution vehicle. extconf.rb contains no build logic; it base64-decodes a Ruby payload, reconstructs a destination URL by XOR-decoding a hex blob with a 4-byte key, and in a detached fork downloads a tarball with curl, extracts it to /tmp/.w1, and runs bash wg_install.sh on the extracted contents. The reconstructed destination is http://45.138.127.89:8092/wgkit.tar.gz — a bare-IP endpoint over plain HTTP, unrelated to any publisher. Execution is gated by anti-analysis checks that refuse to run under CI environment variables, ephemeral/sandbox hostnames, generated usernames matching patterns such as uA\d+/sandbox/tester/analys/scanner, temp or analysis cwd paths, or machine uptime under 30 minutes, and that require developer artifacts (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) to be present. A randomized 20–40 minute sleep further delays detonation. The combination of a cover-story crypto-wallet name, an empty native extension used purely to trigger install-time shell, multi-layer obfuscation of the C2 URL, developer-workstation targeting, and sandbox evasion is a confirmed install-time dropper against developer machines.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021070",
"import_time": "2026-10-05T16:22:56.446864754Z",
"modified_time": "2026-10-05T15:59:47Z",
"sha256": "04f5409730ece37713b6a8d3afddcce30744e213b80759f7ae89478731b0264a",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/hdkey-derive-helper/extconf.rb",
"sha256": "6dfc45b24433c8904150679c99e8917b00d188ef94f53e75bdd4cfdd7da7c7dc",
"tlsh": "d951ba568b8395f54db1d0d044755412fb66bb0d6068a864f3de0868bb5af2ac4f02fd"
},
{
"path": "metadata.yaml",
"sha256": "ef08ed8f3767f11ec4070c1a9528dd4ded078ded5c849d797fa3f6e6ab156d9d",
"tlsh": "5e21ad40ea82e875f101f2d7d8822f03e373c909ff55392265a780d65b89d9e5b17071"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/hdkey-derive-helper/MAL-2026-17602.json"