-= Per source details. Do not edit below this line.=-
ext/utxo-set-utils/extconf.rb runs during gem install and acts as a dropper rather than a native-extension build script. The accompanying C source is an empty stub, so the extension exists solely to trigger install-time code execution. extconf.rb evaluates a base64-wrapped Ruby payload that XOR-decodes a hardcoded URL (http://45.138.122.177:802/wgkit.tar.gz) using key 'usv\x9a', then curls the tarball to /tmp/.w1.tgz, extracts it, and runs bash on wg_install.sh from the archive. Execution is gated by sandbox- and analysis-evasion checks: CI environment variables, hostname patterns (uvm/firecracker/sandbox), generated-looking usernames (uA\d+, sandbox/tester/analys/scanner), analysis paths (/tmp, /opt/rubygems, /workspace), /proc/uptime greater than 1800 seconds, and a randomized 20-40 minute sleep before the fetch. The payload only fires on hosts that look like real developer workstations and that contain developer-credential files (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle), aligning the delivery with harvesting of RubyGems publisher tokens, SSH keys, and Git/npm credentials. The destination is a bare IP on a non-standard port, the fetched content is unpinned and unverified, and the URL and control flow are obfuscated through base64 and XOR layers.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021060",
"import_time": "2026-10-05T16:22:55.600233647Z",
"modified_time": "2026-10-05T15:58:22Z",
"sha256": "7dbd653d2b6e9dead4140f0538bb92092348b726319930b322d6c6346dd7b668",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/utxo-set-utils/extconf.rb",
"sha256": "612db4f410aad69d957b6a27153446b4d9164699750a7947bc94b2bbfcdfb849",
"tlsh": "4551cb568b8395f54db1d0d044399412fb66bb0d6068ad64f3de0868bb5af2ac4f02fd"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/utxo-set-utils/MAL-2026-17613.json"