-= Per source details. Do not edit below this line.=-
The gem declares a native extension whose only real content is a 2-line empty Init stub in ext/merkle-proof-lite/merkle-proof-lite.c; no genuine native code is built. extconf.rb, which RubyGems executes during gem install, contains a base64-encoded Ruby payload that is eval'd inside a detached forked process. The decoded payload XOR-decodes a hardcoded URL to http://45.138.128.177:8092/wgkit.tar.gz, downloads it over plain HTTP to /tmp/.w1.tgz via curl, extracts it, and executes wg_install.sh under bash. Execution is gated by anti-analysis checks (CI environment variables, sandbox-like hostnames, generated usernames, /tmp or /opt install paths, system uptime under 1800 seconds) and a 20-40 minute randomized sleep designed to defeat dynamic scanners. The dropper only fires on hosts where developer-signal files such as ~/.ssh, ~/.gitconfig, and ~/.gem/credentials exist. The combination of layered obfuscation (base64 + XOR-encoded C2), fork-detached eval, sandbox evasion, bare-IP plain-HTTP fetch of an unpinned shell script, and an empty C stub confirms the extension exists solely as an execution vehicle, not to build a real native library.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021062",
"import_time": "2026-10-05T16:22:55.744136085Z",
"modified_time": "2026-10-05T15:58:41Z",
"sha256": "566447bbe57c81d3ad0e7f640951edd848b5a843c8b423ca370d96938d803cba",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/merkle-proof-lite/extconf.rb",
"sha256": "ddde0158956f75e9090e4a7992528bd281312208cbdc4479dc850e434745e480",
"tlsh": "6151ca568b8395f64db1d0d044359412fb667b0e6068a864f3de0868ab5af2ad4f02fd"
},
{
"path": "ext/merkle-proof-lite/merkle-proof-lite.c",
"sha256": "ffc2301e10394df2beb566eeea583de4e229c3ea58390d7dfadf68a14a97f0ae",
"tlsh": "cb9002c3953860434044a6b66329890680e0b6788d547245ad4761e0a5612d53aa61b1"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/merkle-proof-lite/MAL-2026-17609.json"