MAL-2026-17617

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17617
Published
2026-10-05T15:58:32Z
Modified
2026-10-05T16:30:09Z
Summary
Malicious code in web3-sign-helper (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (adeb83bd6e9fada6d55dfe140c32a5ae29d4b3331fb888643ebe064e6d57fc23)

The gem declares a C native extension at ext/web3-sign-helper/extconf.rb, but the shipped C source is a 53-byte empty Init_Web3SignHelper stub and the Ruby library only exposes a static word list — the native-extension declaration exists solely to get extconf.rb executed by RubyGems at install time. Before create_makefile, extconf.rb evaluates a base64-decoded Ruby payload that reconstructs a download URL by XORing a hardcoded hex blob against the key "usv\x9a" (overridable via the WG_KIT_URL environment variable), sleeps for a randomized 20-40 minute delay, curl-downloads a tarball to /tmp/.w1.tgz, extracts it, and runs bash /tmp/.w1/wg_install.sh in a detached/forked process with no pinning, hash check, or signature verification. Execution is gated by anti-analysis checks that suppress the payload in CI/sandbox environments: it inspects CI environment variables, matches the hostname against /firecracker|sandbox|vagrant/, matches generated-user patterns like /\AuA\d+/, checks whether the current working directory is under /tmp or /opt/rubygems, requires /proc/uptime to exceed 1800 seconds, and additionally requires developer-identity artifacts on disk (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle) before firing. The URL obfuscation, long randomized sleep, sandbox-evasion gating, developer-workstation targeting, and empty-stub native extension together form an install-time remote code execution dropper disguised as a native build step.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021061",
            "import_time": "2026-10-05T16:22:55.681056048Z",
            "modified_time": "2026-10-05T15:58:32Z",
            "sha256": "adeb83bd6e9fada6d55dfe140c32a5ae29d4b3331fb888643ebe064e6d57fc23",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / web3-sign-helper

Package

Name
web3-sign-helper
Purl
pkg:gem/web3-sign-helper

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/web3-sign-helper/extconf.rb",
            "sha256": "4699cb4f40e8f9ab766544bb32d11af63a52e553d7b57c0e39e6200e910411f4",
            "tlsh": "5c51cb568b8395f54db1d0d044795413fb667b0d6068ac64f3de0868bb5af2ac4f02fd"
        },
        {
            "path": "ext/web3-sign-helper/web3-sign-helper.c",
            "sha256": "7906af16f00c5ff6b3c9816071dbcb5dd181c65c933e8f3159078ae88dd82c78",
            "tlsh": "709002c2c53870024000efe1932d51498090b5544f59754669032156a750294396b5b4"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json"