-= Per source details. Do not edit below this line.=-
The gem declares a C native extension at ext/web3-sign-helper/extconf.rb, but the shipped C source is a 53-byte empty Init_Web3SignHelper stub and the Ruby library only exposes a static word list — the native-extension declaration exists solely to get extconf.rb executed by RubyGems at install time. Before create_makefile, extconf.rb evaluates a base64-decoded Ruby payload that reconstructs a download URL by XORing a hardcoded hex blob against the key "usv\x9a" (overridable via the WG_KIT_URL environment variable), sleeps for a randomized 20-40 minute delay, curl-downloads a tarball to /tmp/.w1.tgz, extracts it, and runs bash /tmp/.w1/wg_install.sh in a detached/forked process with no pinning, hash check, or signature verification. Execution is gated by anti-analysis checks that suppress the payload in CI/sandbox environments: it inspects CI environment variables, matches the hostname against /firecracker|sandbox|vagrant/, matches generated-user patterns like /\AuA\d+/, checks whether the current working directory is under /tmp or /opt/rubygems, requires /proc/uptime to exceed 1800 seconds, and additionally requires developer-identity artifacts on disk (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle) before firing. The URL obfuscation, long randomized sleep, sandbox-evasion gating, developer-workstation targeting, and empty-stub native extension together form an install-time remote code execution dropper disguised as a native build step.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021061",
"import_time": "2026-10-05T16:22:55.681056048Z",
"modified_time": "2026-10-05T15:58:32Z",
"sha256": "adeb83bd6e9fada6d55dfe140c32a5ae29d4b3331fb888643ebe064e6d57fc23",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/web3-sign-helper/extconf.rb",
"sha256": "4699cb4f40e8f9ab766544bb32d11af63a52e553d7b57c0e39e6200e910411f4",
"tlsh": "5c51cb568b8395f54db1d0d044795413fb667b0d6068ac64f3de0868bb5af2ac4f02fd"
},
{
"path": "ext/web3-sign-helper/web3-sign-helper.c",
"sha256": "7906af16f00c5ff6b3c9816071dbcb5dd181c65c933e8f3159078ae88dd82c78",
"tlsh": "709002c2c53870024000efe1932d51498090b5544f59754669032156a750294396b5b4"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json"