MAL-2026-17602

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/hdkey-derive-helper/MAL-2026-17602.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17602
Published
2026-10-05T15:59:47Z
Modified
2026-10-05T16:30:07Z
Summary
Malicious code in hdkey-derive-helper (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (04f5409730ece37713b6a8d3afddcce30744e213b80759f7ae89478731b0264a)

The gem presents itself as a BIP32/mnemonic derivation helper but ships only a wordlist stub and a 56-byte empty C file (ext/hdkey-derive-helper/hdkey-derive-helper.c, body void Init_HdkeyDeriveHelper(void) {}) registered as a native extension. Because RubyGems auto-executes extconf.rb during gem install, the extension exists solely as an execution vehicle. extconf.rb contains no build logic; it base64-decodes a Ruby payload, reconstructs a destination URL by XOR-decoding a hex blob with a 4-byte key, and in a detached fork downloads a tarball with curl, extracts it to /tmp/.w1, and runs bash wg_install.sh on the extracted contents. The reconstructed destination is http://45.138.127.89:8092/wgkit.tar.gz — a bare-IP endpoint over plain HTTP, unrelated to any publisher. Execution is gated by anti-analysis checks that refuse to run under CI environment variables, ephemeral/sandbox hostnames, generated usernames matching patterns such as uA\d+/sandbox/tester/analys/scanner, temp or analysis cwd paths, or machine uptime under 30 minutes, and that require developer artifacts (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) to be present. A randomized 20–40 minute sleep further delays detonation. The combination of a cover-story crypto-wallet name, an empty native extension used purely to trigger install-time shell, multi-layer obfuscation of the C2 URL, developer-workstation targeting, and sandbox evasion is a confirmed install-time dropper against developer machines.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021070",
            "import_time": "2026-10-05T16:22:56.446864754Z",
            "modified_time": "2026-10-05T15:59:47Z",
            "sha256": "04f5409730ece37713b6a8d3afddcce30744e213b80759f7ae89478731b0264a",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / hdkey-derive-helper

Package

Name
hdkey-derive-helper
Purl
pkg:gem/hdkey-derive-helper

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/hdkey-derive-helper/extconf.rb",
            "sha256": "6dfc45b24433c8904150679c99e8917b00d188ef94f53e75bdd4cfdd7da7c7dc",
            "tlsh": "d951ba568b8395f54db1d0d044755412fb66bb0d6068a864f3de0868bb5af2ac4f02fd"
        },
        {
            "path": "metadata.yaml",
            "sha256": "ef08ed8f3767f11ec4070c1a9528dd4ded078ded5c849d797fa3f6e6ab156d9d",
            "tlsh": "5e21ad40ea82e875f101f2d7d8822f03e373c909ff55392265a780d65b89d9e5b17071"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/hdkey-derive-helper/MAL-2026-17602.json"