MAL-2026-17609

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/merkle-proof-lite/MAL-2026-17609.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17609
Published
2026-10-05T15:58:41Z
Modified
2026-10-05T16:30:07Z
Summary
Malicious code in merkle-proof-lite (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (566447bbe57c81d3ad0e7f640951edd848b5a843c8b423ca370d96938d803cba)

The gem declares a native extension whose only real content is a 2-line empty Init stub in ext/merkle-proof-lite/merkle-proof-lite.c; no genuine native code is built. extconf.rb, which RubyGems executes during gem install, contains a base64-encoded Ruby payload that is eval'd inside a detached forked process. The decoded payload XOR-decodes a hardcoded URL to http://45.138.128.177:8092/wgkit.tar.gz, downloads it over plain HTTP to /tmp/.w1.tgz via curl, extracts it, and executes wg_install.sh under bash. Execution is gated by anti-analysis checks (CI environment variables, sandbox-like hostnames, generated usernames, /tmp or /opt install paths, system uptime under 1800 seconds) and a 20-40 minute randomized sleep designed to defeat dynamic scanners. The dropper only fires on hosts where developer-signal files such as ~/.ssh, ~/.gitconfig, and ~/.gem/credentials exist. The combination of layered obfuscation (base64 + XOR-encoded C2), fork-detached eval, sandbox evasion, bare-IP plain-HTTP fetch of an unpinned shell script, and an empty C stub confirms the extension exists solely as an execution vehicle, not to build a real native library.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021062",
            "import_time": "2026-10-05T16:22:55.744136085Z",
            "modified_time": "2026-10-05T15:58:41Z",
            "sha256": "566447bbe57c81d3ad0e7f640951edd848b5a843c8b423ca370d96938d803cba",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / merkle-proof-lite

Package

Name
merkle-proof-lite
Purl
pkg:gem/merkle-proof-lite

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/merkle-proof-lite/extconf.rb",
            "sha256": "ddde0158956f75e9090e4a7992528bd281312208cbdc4479dc850e434745e480",
            "tlsh": "6151ca568b8395f64db1d0d044359412fb667b0e6068a864f3de0868ab5af2ad4f02fd"
        },
        {
            "path": "ext/merkle-proof-lite/merkle-proof-lite.c",
            "sha256": "ffc2301e10394df2beb566eeea583de4e229c3ea58390d7dfadf68a14a97f0ae",
            "tlsh": "cb9002c3953860434044a6b66329890680e0b6788d547245ad4761e0a5612d53aa61b1"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/merkle-proof-lite/MAL-2026-17609.json"