MAL-2026-17612

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/tx-broadcast-utils/MAL-2026-17612.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17612
Published
2026-10-05T16:00:05Z
Modified
2026-10-05T16:30:07Z
Summary
Malicious code in tx-broadcast-utils (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (60efdf159c3ce8550c985b3f19cbe72f2bfcae0266cb63fb8c0dd458b56b9901)

The gem's native-extension script (ext/.../extconf.rb) embeds a base64-encoded Ruby payload that is eval'd at gem install time. The payload double-forks and detaches a background process which sleeps 20-40 minutes, reconstructs a C2 URL by XOR-decoding a hex blob to http://45.138.17.70:809/wgkit.tar.gz, downloads the tarball to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes wg_install.sh as the installing user. Execution is gated on anti-analysis checks that suppress the payload in CI, ephemeral/sandbox hostnames, generated usernames matching /uA\d+/, paths under /tmp or /opt/rubygems, and hosts with short uptime, and requires developer-machine signals such as ~/.ssh, ~/.gitconfig, and ~/.gem/credentials before firing. The advertised purpose (Bitcoin transaction broadcast helpers over public esplora endpoints) is a decoy: the shipped library only exposes a truncated BIP39 word list with no broadcast code, and the native extension's C source is an empty Init_ stub. The extconf.rb dropper is the gem's only functional component.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021072",
            "import_time": "2026-10-05T16:22:56.571110292Z",
            "modified_time": "2026-10-05T16:00:05Z",
            "sha256": "60efdf159c3ce8550c985b3f19cbe72f2bfcae0266cb63fb8c0dd458b56b9901",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / tx-broadcast-utils

Package

Name
tx-broadcast-utils
Purl
pkg:gem/tx-broadcast-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/tx-broadcast-utils/extconf.rb",
            "sha256": "a7a8eba595c9fafeac87123622ac4721f3f40fb8baf2dbcf24e0bbab77e0dc15",
            "tlsh": "8a51ba568b8395f54db1d0d044355412fb667b0e6068ac64f3de0868ab5af2ac4f02fd"
        },
        {
            "path": "lib/tx-broadcast-utils.rb",
            "sha256": "457fa727375c1a101018e7c4839f2d4f5a0780c67e2db34b6a9d258467f72fd8",
            "tlsh": "3701a25da10a8490ffd16db27223dc467e4a4a3311092cf0f1bc42915feb8e98a7f954"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/tx-broadcast-utils/MAL-2026-17612.json"