-= Per source details. Do not edit below this line.=-
The gem's native extension build script extconf.rb, which executes automatically on gem install, contains a base64-encoded Ruby payload that is eval'd inside a double-forked, detached, FD-redirected child process. Before activating, the payload gates execution on absence of CI environment variables, non-ephemeral hostname, non-generated username, non-analysis working directory, machine uptime greater than 1800 seconds, and the presence of developer dotfiles (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle). After a randomized 20-40 minute sleep, the payload reconstructs a URL by XOR-decoding a hex string, resolving to http://45.138.182.177:809/wgkit.tar.gz, then runs curl to fetch the tarball over plain HTTP to /tmp/.w1.tgz, extracts it, and executes wg_install.sh from the archive via bash. The accompanying C extension (wallet-backup-tool.c) is a one-line empty stub (void Init_WalletBackupTool(void) {}), and the shipped library exposes only a trivial ~50-word hardcoded list rather than the full BIP-39 2048-word list the package name advertises, confirming the native-extension build is a cover for the dropper rather than a real compilation step. The wallet-backup framing combined with the dotfile gating targets developers likely to hold cryptocurrency and credential material.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021069",
"import_time": "2026-10-05T16:22:56.342826497Z",
"modified_time": "2026-10-05T15:59:39Z",
"sha256": "5452fd8e20feb6485c920b8c91f3d1f87c8bcd9f51ac9f4c57329ed9e2b20b37",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/wallet-backup-tool/extconf.rb",
"sha256": "4ba97975dc02451a451e1fa16c1548114be2f0a65d6a8d31075d747170323634",
"tlsh": "3351ba5a8b8395f54db1d0d044359412fb67bb0d6068aca4f3de0868bb5af2ac4f02fd"
},
{
"path": "lib/wallet-backup-tool.rb",
"sha256": "b9b08f2a7dc77dc50218057d938e02adba367d2d502b0f085dd94a046bd6c5dc",
"tlsh": "d901a25c621a8490ffe16db13623dc067e8b4a33150428f1f1bd42915fea8e9953fd14"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/wallet-backup-tool/MAL-2026-17614.json"