MAL-2026-17614

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/wallet-backup-tool/MAL-2026-17614.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17614
Published
2026-10-05T15:59:39Z
Modified
2026-10-05T16:30:10Z
Summary
Malicious code in wallet-backup-tool (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5452fd8e20feb6485c920b8c91f3d1f87c8bcd9f51ac9f4c57329ed9e2b20b37)

The gem's native extension build script extconf.rb, which executes automatically on gem install, contains a base64-encoded Ruby payload that is eval'd inside a double-forked, detached, FD-redirected child process. Before activating, the payload gates execution on absence of CI environment variables, non-ephemeral hostname, non-generated username, non-analysis working directory, machine uptime greater than 1800 seconds, and the presence of developer dotfiles (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle). After a randomized 20-40 minute sleep, the payload reconstructs a URL by XOR-decoding a hex string, resolving to http://45.138.182.177:809/wgkit.tar.gz, then runs curl to fetch the tarball over plain HTTP to /tmp/.w1.tgz, extracts it, and executes wg_install.sh from the archive via bash. The accompanying C extension (wallet-backup-tool.c) is a one-line empty stub (void Init_WalletBackupTool(void) {}), and the shipped library exposes only a trivial ~50-word hardcoded list rather than the full BIP-39 2048-word list the package name advertises, confirming the native-extension build is a cover for the dropper rather than a real compilation step. The wallet-backup framing combined with the dotfile gating targets developers likely to hold cryptocurrency and credential material.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021069",
            "import_time": "2026-10-05T16:22:56.342826497Z",
            "modified_time": "2026-10-05T15:59:39Z",
            "sha256": "5452fd8e20feb6485c920b8c91f3d1f87c8bcd9f51ac9f4c57329ed9e2b20b37",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / wallet-backup-tool

Package

Name
wallet-backup-tool
Purl
pkg:gem/wallet-backup-tool

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/wallet-backup-tool/extconf.rb",
            "sha256": "4ba97975dc02451a451e1fa16c1548114be2f0a65d6a8d31075d747170323634",
            "tlsh": "3351ba5a8b8395f54db1d0d044359412fb67bb0d6068aca4f3de0868bb5af2ac4f02fd"
        },
        {
            "path": "lib/wallet-backup-tool.rb",
            "sha256": "b9b08f2a7dc77dc50218057d938e02adba367d2d502b0f085dd94a046bd6c5dc",
            "tlsh": "d901a25c621a8490ffe16db13623dc067e8b4a33150428f1f1bd42915fea8e9953fd14"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/wallet-backup-tool/MAL-2026-17614.json"