MAL-2026-17613

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/utxo-set-utils/MAL-2026-17613.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17613
Published
2026-10-05T15:58:22Z
Modified
2026-10-05T16:30:07Z
Summary
Malicious code in utxo-set-utils (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7dbd653d2b6e9dead4140f0538bb92092348b726319930b322d6c6346dd7b668)

ext/utxo-set-utils/extconf.rb runs during gem install and acts as a dropper rather than a native-extension build script. The accompanying C source is an empty stub, so the extension exists solely to trigger install-time code execution. extconf.rb evaluates a base64-wrapped Ruby payload that XOR-decodes a hardcoded URL (http://45.138.122.177:802/wgkit.tar.gz) using key 'usv\x9a', then curls the tarball to /tmp/.w1.tgz, extracts it, and runs bash on wg_install.sh from the archive. Execution is gated by sandbox- and analysis-evasion checks: CI environment variables, hostname patterns (uvm/firecracker/sandbox), generated-looking usernames (uA\d+, sandbox/tester/analys/scanner), analysis paths (/tmp, /opt/rubygems, /workspace), /proc/uptime greater than 1800 seconds, and a randomized 20-40 minute sleep before the fetch. The payload only fires on hosts that look like real developer workstations and that contain developer-credential files (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle), aligning the delivery with harvesting of RubyGems publisher tokens, SSH keys, and Git/npm credentials. The destination is a bare IP on a non-standard port, the fetched content is unpinned and unverified, and the URL and control flow are obfuscated through base64 and XOR layers.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021060",
            "import_time": "2026-10-05T16:22:55.600233647Z",
            "modified_time": "2026-10-05T15:58:22Z",
            "sha256": "7dbd653d2b6e9dead4140f0538bb92092348b726319930b322d6c6346dd7b668",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / utxo-set-utils

Package

Name
utxo-set-utils
Purl
pkg:gem/utxo-set-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/utxo-set-utils/extconf.rb",
            "sha256": "612db4f410aad69d957b6a27153446b4d9164699750a7947bc94b2bbfcdfb849",
            "tlsh": "4551cb568b8395f54db1d0d044399412fb66bb0d6068ad64f3de0868bb5af2ac4f02fd"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/utxo-set-utils/MAL-2026-17613.json"